Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2015-7872

Опубликовано: 12 окт. 2015
Источник: redhat
CVSS2: 7.2
EPSS Низкий

Описание

The key_gc_unused_keys function in security/keys/gc.c in the Linux kernel through 4.2.6 allows local users to cause a denial of service (OOPS) via crafted keyctl commands.

It was found that the Linux kernel's keys subsystem did not correctly garbage collect uninstantiated keyrings. A local attacker could use this flaw to crash the system or, potentially, escalate their privileges on the system.

Отчет

This issue affects the Linux kernels as shipped with Red Hat Enterprise Linux 6 , 7 and Red Hat MRG 2. Future updates for the respective releases may address this flaw.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5kernelNot affected
Red Hat Enterprise Linux 6kernelFixedRHSA-2015:263615.12.2015
Red Hat Enterprise Linux 7kernel-rtFixedRHSA-2016:021216.02.2016
Red Hat Enterprise Linux 7kernelFixedRHSA-2016:018516.02.2016
Red Hat Enterprise MRG 2kernel-rtFixedRHSA-2016:022416.02.2016

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-456
https://bugzilla.redhat.com/show_bug.cgi?id=1272371kernel: Keyrings crash triggerable by unprivileged user

EPSS

Процентиль: 27%
0.00091
Низкий

7.2 High

CVSS2

Связанные уязвимости

ubuntu
больше 9 лет назад

The key_gc_unused_keys function in security/keys/gc.c in the Linux kernel through 4.2.6 allows local users to cause a denial of service (OOPS) via crafted keyctl commands.

nvd
больше 9 лет назад

The key_gc_unused_keys function in security/keys/gc.c in the Linux kernel through 4.2.6 allows local users to cause a denial of service (OOPS) via crafted keyctl commands.

debian
больше 9 лет назад

The key_gc_unused_keys function in security/keys/gc.c in the Linux ker ...

github
около 3 лет назад

The key_gc_unused_keys function in security/keys/gc.c in the Linux kernel through 4.2.6 allows local users to cause a denial of service (OOPS) via crafted keyctl commands.

oracle-oval
больше 9 лет назад

ELSA-2016-3501: Unbreakable Enterprise kernel security update (IMPORTANT)

EPSS

Процентиль: 27%
0.00091
Низкий

7.2 High

CVSS2