CVE-2009-3624
published 2009-11-02CVE-2009-3624: The get_instantiation_keyring function in security/keys/keyctl.c in the KEYS subsystem in the Linux kernel before 2.6.32-rc5 does not properly maintain the…
PriorityP418medium4.6CVSS 2.0
AVLACLAuNCPIPAP
EPSS
0.37%
29.8th percentile
The get_instantiation_keyring function in security/keys/keyctl.c in the KEYS subsystem in the Linux kernel before 2.6.32-rc5 does not properly maintain the reference count of a keyring, which allows local users to gain privileges or cause a denial of service (OOPS) via vectors involving calls to this function without specifying a keyring by ID, as demonstrated by a series of keyctl request2 and keyctl list commands.
Affected
339 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| linux | kernel | — | — |
| linux | kernel | — | — |
| linux | linux_kernel | <= 2.6.32 | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
CVSS provenance
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
vendor_ubuntu4.9MEDIUM
vendor_redhat4.6MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-gx7p-6h8g-757g: The get_instantiation_keyring function in security/keys/keyctl
ghsa_unreviewed·2022-05-02
CVE-2009-3624 [MEDIUM] GHSA-gx7p-6h8g-757g: The get_instantiation_keyring function in security/keys/keyctl
The get_instantiation_keyring function in security/keys/keyctl.c in the KEYS subsystem in the Linux kernel before 2.6.32-rc5 does not properly maintain the reference count of a keyring, which allows local users to gain privileges or cause a denial of service (OOPS) via vectors involving calls to this function without specifying a keyring by ID, as demonstrated by a series of keyctl request2 and keyctl list commands.
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2009-12-05·CVSS 4.9
CVE-2009-3726 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Linux kernel vulnerabilities
It was discovered that the AX.25 network subsystem did not correctly
check integer signedness in certain setsockopt calls. A local attacker
could exploit this to crash the system, leading to a denial of service.
Ubuntu 9.10 was not affected. (CVE-2009-2909)
Jan Beulich discovered that the kernel could leak register contents to
32-bit processes that were switched to 64-bit mode. A local attacker
could run a specially crafted binary to read register values from an
earlier process, leading to a loss of privacy. (CVE-2009-2910)
Dave Jones discovered that the gdth SCSI driver did not correctly validate
array indexes in certain ioctl calls. A local attacker could exploit
this to crash the system or gain elevated privil
Red Hat
kernel: get_instantiation_keyring() should inc the keyring refcount in all cases
vendor_redhat·2009-10-15·CVSS 4.6
CVE-2009-3624 [MEDIUM] kernel: get_instantiation_keyring() should inc the keyring refcount in all cases
kernel: get_instantiation_keyring() should inc the keyring refcount in all cases
The get_instantiation_keyring function in security/keys/keyctl.c in the KEYS subsystem in the Linux kernel before 2.6.32-rc5 does not properly maintain the reference count of a keyring, which allows local users to gain privileges or cause a denial of service (OOPS) via vectors involving calls to this function without specifying a keyring by ID, as demonstrated by a series of keyctl request2 and keyctl list commands.
Statement: Not vulnerable. This issue did not affect the versions of the Linux kernel as shipped with Red Hat Enterprise Linux 3, 4, 5, or Red Hat Enterprise MRG. Those versions do not include the upstream patch that introduced this vulnerability.
No detection rules found.
No public exploits indexed.
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=21279cfa107af07ef985539ac0de2152b9cba5f5http://lists.opensuse.org/opensuse-security-announce/2010-01/msg00000.htmlhttp://marc.info/?l=oss-security&m=125619420905341&w=2http://marc.info/?l=oss-security&m=125624091417161&w=2http://secunia.com/advisories/37086http://secunia.com/advisories/38017http://twitter.com/spendergrsec/statuses/4916661870http://www.kernel.org/pub/linux/kernel/v2.6/testing/ChangeLog-2.6.32-rc5http://www.ubuntu.com/usn/usn-864-1http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=21279cfa107af07ef985539ac0de2152b9cba5f5http://lists.opensuse.org/opensuse-security-announce/2010-01/msg00000.htmlhttp://marc.info/?l=oss-security&m=125619420905341&w=2http://marc.info/?l=oss-security&m=125624091417161&w=2http://secunia.com/advisories/37086http://secunia.com/advisories/38017http://twitter.com/spendergrsec/statuses/4916661870http://www.kernel.org/pub/linux/kernel/v2.6/testing/ChangeLog-2.6.32-rc5http://www.ubuntu.com/usn/usn-864-1
2009-11-02
Published