Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2015-8539

Опубликовано: 09 дек. 2015
Источник: redhat
CVSS3: 7.8
CVSS2: 7.2

Описание

The KEYS subsystem in the Linux kernel before 4.4 allows local users to gain privileges or cause a denial of service (BUG) via crafted keyctl commands that negatively instantiate a key, related to security/keys/encrypted-keys/encrypted.c, security/keys/trusted.c, and security/keys/user_defined.c.

A flaw was found in the Linux kernel's key management system where it was possible for an attacker to escalate privileges or crash the machine. If a user key gets negatively instantiated, an error code is cached in the payload area. A negatively instantiated key may be then be positively instantiated by updating it with valid data. However, the ->update key type method must be aware that the error code may be there.

Отчет

This issue does not affect the Linux kernels as shipped with Red Hat Enterprise Linux 4 and 5. This issue does affect the kernels shipped with Red Hat Enterprise Linux 6, 7, MRG-2 and realtime kernels and plans to be addressed in a future update.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 4kernelNot affected
Red Hat Enterprise Linux 5kernelNot affected
Red Hat Enterprise Linux 6kernelNot affected
Red Hat Enterprise Linux 7kernel-rtFixedRHSA-2018:015225.01.2018
Red Hat Enterprise Linux 7kernelFixedRHSA-2018:015125.01.2018
Red Hat Enterprise MRG 2kernel-rtFixedRHSA-2018:018125.01.2018

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-667
https://bugzilla.redhat.com/show_bug.cgi?id=1284450kernel: local privesc in key management

7.8 High

CVSS3

7.2 High

CVSS2

Связанные уязвимости

CVSS3: 7.8
ubuntu
больше 9 лет назад

The KEYS subsystem in the Linux kernel before 4.4 allows local users to gain privileges or cause a denial of service (BUG) via crafted keyctl commands that negatively instantiate a key, related to security/keys/encrypted-keys/encrypted.c, security/keys/trusted.c, and security/keys/user_defined.c.

CVSS3: 7.8
nvd
больше 9 лет назад

The KEYS subsystem in the Linux kernel before 4.4 allows local users to gain privileges or cause a denial of service (BUG) via crafted keyctl commands that negatively instantiate a key, related to security/keys/encrypted-keys/encrypted.c, security/keys/trusted.c, and security/keys/user_defined.c.

CVSS3: 7.8
debian
больше 9 лет назад

The KEYS subsystem in the Linux kernel before 4.4 allows local users t ...

suse-cvrf
больше 9 лет назад

Security update for kernel live patch SP1 1

suse-cvrf
больше 9 лет назад

Security update for kernel live patch 9

7.8 High

CVSS3

7.2 High

CVSS2

Уязвимость CVE-2015-8539