PT-2014-1967 · Linux+5 · Linux Kernel+5
Andrey Ryabinin
+1
·
Publicado
2014-09-16
·
Atualizado
2023-02-12
·
CVE-2017-2647
CVSS v3.1
7.8
Alta
| Vetor | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel versions prior to 3.18
Description
The issue is related to the KEYS subsystem in the Linux kernel, which allows local users to gain privileges or cause a denial of service. This can happen through vectors involving a NULL value for a certain match field, related to the keyring search iterator function in keyring.c. The exploitation of this issue can lead to a NULL pointer dereference and system crash.
Recommendations
For Linux kernel versions prior to 3.18, update to version 3.18 or later to resolve the issue. As a temporary workaround, consider restricting access to the keyring search iterator function in keyring.c to minimize the risk of exploitation.
Correção
DoS
NULL Pointer Dereference
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Alt Linux
Centos
Linux Kernel
Red Hat
Suse
Ubuntu