CVE-2010-2960NULL Pointer Dereference in Kernel

Severity
7.8HIGHNVD
EPSS
0.1%
top 72.30%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 8
Latest updateMay 13

Description

The keyctl_session_to_parent function in security/keys/keyctl.c in the Linux kernel 2.6.35.4 and earlier expects that a certain parent session keyring exists, which allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact via a KEYCTL_SESSION_TO_PARENT argument to the keyctl function.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages3 packages

Also affects: Ubuntu Linux 10.04, 10.10, 6.06, 8.04, 9.04, 9.10

Patches

🔴Vulnerability Details

2
GHSA
GHSA-gx25-2frw-gvqr: The keyctl_session_to_parent function in security/keys/keyctl2022-05-13
CVEList
CVE-2010-2960: The keyctl_session_to_parent function in security/keys/keyctl2010-09-08

📋Vendor Advisories

6
Ubuntu
Linux kernel (OMAP4) vulnerabilities2011-04-20
Ubuntu
Linux Kernel vulnerabilities (Marvell Dove)2011-03-25
Ubuntu
Linux kernel vulnerabilities2011-03-03
Ubuntu
Linux kernel vulnerabilities2010-10-19
Red Hat
keyctl_session_to_parent NULL deref system crash2010-09-02

💬Community

1
Bugzilla
CVE-2010-2960 keyctl_session_to_parent NULL deref system crash2010-08-26
CVE-2010-2960 — NULL Pointer Dereference in Kernel | cvebase