CVE-2013-1792
published 2013-03-22CVE-2013-1792: Race condition in the install_user_keyrings function in security/keys/process_keys.c in the Linux kernel before 3.8.3 allows local users to cause a denial of…
PriorityP414medium4.7CVSS 2.0
AVLACMAuNCNINAC
EPSS
0.29%
21.1th percentile
Race condition in the install_user_keyrings function in security/keys/process_keys.c in the Linux kernel before 3.8.3 allows local users to cause a denial of service (NULL pointer dereference and system crash) via crafted keyctl system calls that trigger keyring operations in simultaneous threads.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 3.2.41-1 (bookworm) | linux 3.2.41-1 (bookworm) |
| linux | linux_kernel | <= 3.8.2 | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 0 < 3.2.41-1 | 3.2.41-1 |
| linux | linux_kernel | >= 0 < 3.2.41-1 | 3.2.41-1 |
| linux | linux_kernel | >= 0 < 3.2.41-1 | 3.2.41-1 |
| linux | linux_kernel | >= 0 < 3.2.41-1 | 3.2.41-1 |
CVSS provenance
nvdv2.04.7MEDIUMAV:L/AC:M/Au:N/C:N/I:N/A:C
osv4.7MEDIUM
vendor_ubuntu6.2MEDIUM
vendor_debian4.7MEDIUM
vendor_redhat4.7MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Linux kernel (EC2) vulnerabilities
vendor_ubuntu·2013-04-09·CVSS 1.9
CVE-2012-6537 [LOW] Linux kernel (EC2) vulnerabilities
Title: Linux kernel (EC2) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Mathias Krause discovered several errors in the Linux kernel's xfrm_user
implementation. A local attacker could exploit these flaws to examine parts
of kernel memory. (CVE-2012-6537)
Mathias Krause discovered information leak in the Linux kernel's compat
ioctl interface. A local user could exploit the flaw to examine parts of
kernel stack memory (CVE-2012-6539)
Mathias Krause discovered an information leak in the Linux kernel's
getsockopt for IP_VS_SO_GET_TIMEOUT. A local user could exploit this flaw
to examine parts of kernel stack memory. (CVE-2012-6540)
Emese Revfy discovered that in the Linux kernel signal handlers could leak
address information across an exec, making it possible t
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2013-04-08·CVSS 3.6
CVE-2013-0914 [LOW] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
Emese Revfy discovered that in the Linux kernel signal handlers could leak
address information across an exec, making it possible to by pass ASLR
(Address Space Layout Randomization). A local user could use this flaw to
by pass ASLR to reliably deliver an exploit payload that would otherwise be
stopped (by ASLR). (CVE-2013-0914)
A memory use after free error was discover in the Linux kernel's tmpfs
filesystem. A local user could exploit this flaw to gain privileges or
cause a denial of service (system crash). (CVE-2013-1767)
Mateusz Guzik discovered a race in the Linux kernel's keyring. A local user
could exploit this flaw to cause a denial of service (system crash).
(CVE-2013-1792)
Mathias
Ubuntu
Linux kernel (OMAP4) vulnerabilities
vendor_ubuntu·2013-04-08·CVSS 6.2
CVE-2013-0228 [MEDIUM] Linux kernel (OMAP4) vulnerabilities
Title: Linux kernel (OMAP4) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Andrew Jones discovered a flaw with the xen_iret function in Linux kernel's
Xen virtualizeation. In the 32-bit Xen paravirt platform an unprivileged
guest OS user could exploit this flaw to cause a denial of service (crash
the system) or gain guest OS privilege. (CVE-2013-0228)
Emese Revfy discovered that in the Linux kernel signal handlers could leak
address information across an exec, making it possible to by pass ASLR
(Address Space Layout Randomization). A local user could use this flaw to
by pass ASLR to reliably deliver an exploit payload that would otherwise be
stopped (by ASLR). (CVE-2013-0914)
A memory use after free error was discover in the Linux kernel's tmpfs
filesystem.
Ubuntu
Linux kernel (Quantal HWE) vulnerabilities
vendor_ubuntu·2013-04-08·CVSS 6.2
CVE-2013-0228 [MEDIUM] Linux kernel (Quantal HWE) vulnerabilities
Title: Linux kernel (Quantal HWE) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Andrew Jones discovered a flaw with the xen_iret function in Linux kernel's
Xen virtualizeation. In the 32-bit Xen paravirt platform an unprivileged
guest OS user could exploit this flaw to cause a denial of service (crash
the system) or gain guest OS privilege. (CVE-2013-0228)
Emese Revfy discovered that in the Linux kernel signal handlers could leak
address information across an exec, making it possible to by pass ASLR
(Address Space Layout Randomization). A local user could use this flaw to
by pass ASLR to reliably deliver an exploit payload that would otherwise be
stopped (by ASLR). (CVE-2013-0914)
A memory use after free error was discover in the Linux kernel's tmpfs
filesy
Ubuntu
Linux kernel (OMAP4) vulnerabilities
vendor_ubuntu·2013-04-08·CVSS 3.6
CVE-2013-0914 [LOW] Linux kernel (OMAP4) vulnerabilities
Title: Linux kernel (OMAP4) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Emese Revfy discovered that in the Linux kernel signal handlers could leak
address information across an exec, making it possible to by pass ASLR
(Address Space Layout Randomization). A local user could use this flaw to
by pass ASLR to reliably deliver an exploit payload that would otherwise be
stopped (by ASLR). (CVE-2013-0914)
A memory use after free error was discover in the Linux kernel's tmpfs
filesystem. A local user could exploit this flaw to gain privileges or
cause a denial of service (system crash). (CVE-2013-1767)
Mateusz Guzik discovered a race in the Linux kernel's keyring. A local user
could exploit this flaw to cause a denial of service (system crash).
(CVE-2013-1792)
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2013-04-08·CVSS 1.9
CVE-2012-6537 [LOW] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
Mathias Krause discovered several errors in the Linux kernel's xfrm_user
implementation. A local attacker could exploit these flaws to examine parts
of kernel memory. (CVE-2012-6537)
Mathias Krause discovered information leak in the Linux kernel's compat
ioctl interface. A local user could exploit the flaw to examine parts of
kernel stack memory (CVE-2012-6539)
Mathias Krause discovered an information leak in the Linux kernel's
getsockopt for IP_VS_SO_GET_TIMEOUT. A local user could exploit this flaw
to examine parts of kernel stack memory. (CVE-2012-6540)
Emese Revfy discovered that in the Linux kernel signal handlers could leak
address information across an exec, making it possible to by p
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2013-04-08·CVSS 6.2
CVE-2013-0228 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
Andrew Jones discovered a flaw with the xen_iret function in Linux kernel's
Xen virtualizeation. In the 32-bit Xen paravirt platform an unprivileged
guest OS user could exploit this flaw to cause a denial of service (crash
the system) or gain guest OS privilege. (CVE-2013-0228)
Emese Revfy discovered that in the Linux kernel signal handlers could leak
address information across an exec, making it possible to by pass ASLR
(Address Space Layout Randomization). A local user could use this flaw to
by pass ASLR to reliably deliver an exploit payload that would otherwise be
stopped (by ASLR). (CVE-2013-0914)
A memory use after free error was discover in the Linux kernel's tmpfs
filesystem. A local
Ubuntu
Linux kernel (Oneiric backport) vulnerabilities
vendor_ubuntu·2013-04-04·CVSS 3.6
CVE-2013-0914 [LOW] Linux kernel (Oneiric backport) vulnerabilities
Title: Linux kernel (Oneiric backport) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Emese Revfy discovered that in the Linux kernel signal handlers could leak
address information across an exec, making it possible to bypass ASLR
(Address Space Layout Randomization). A local user could use this flaw to
bypass ASLR to reliably deliver an exploit payload that would otherwise be
stopped (by ASLR). (CVE-2013-0914)
A memory use after free error was discovered in the Linux kernel's tmpfs
filesystem. A local user could exploit this flaw to gain privileges or
cause a denial of service (system crash). (CVE-2013-1767)
Mateusz Guzik discovered a race in the Linux kernel's keyring. A local user
could exploit this flaw to cause a denial of service (system crash).
(CVE-2
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2013-04-02·CVSS 3.6
CVE-2013-0914 [LOW] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
Emese Revfy discovered that in the Linux kernel signal handlers could leak
address information across an exec, making it possible to by pass ASLR
(Address Space Layout Randomization). A local user could use this flaw to
by pass ASLR to reliably deliver an exploit payload that would otherwise be
stopped (by ASLR). (CVE-2013-0914)
A memory use after free error was discover in the Linux kernel's tmpfs
filesystem. A local user could exploit this flaw to gain privileges or
cause a denial of service (system crash). (CVE-2013-1767)
Mateusz Guzik discovered a race in the Linux kernel's keyring. A local user
could exploit this flaw to cause a denial of service (system crash).
(CVE-2013-1792)
Instruct
Red Hat
Kernel: keys: race condition in install_user_keyrings()
vendor_redhat·2013-03-06·CVSS 4.7
CVE-2013-1792 [MEDIUM] Kernel: keys: race condition in install_user_keyrings()
Kernel: keys: race condition in install_user_keyrings()
Race condition in the install_user_keyrings function in security/keys/process_keys.c in the Linux kernel before 3.8.3 allows local users to cause a denial of service (NULL pointer dereference and system crash) via crafted keyctl system calls that trigger keyring operations in simultaneous threads.
Statement: This issue does not affect the versions of the kernel package as shipped with Red Hat Enterprise Linux 5.
This issue affects the version of Linux kernel as shipped with Red Hat Enterprise Linux 6 and Red Hat Enterprise MRG 2. Future kernel updates for Red Hat Enterprise MRG 2 may address this issue.
Package: kernel (Red Hat Enterprise Linux 5) - Not affected
Debian
CVE-2013-1792: linux - Race condition in the install_user_keyrings function in security/keys/process_ke...
vendor_debian·2013·CVSS 4.7
CVE-2013-1792 [MEDIUM] CVE-2013-1792: linux - Race condition in the install_user_keyrings function in security/keys/process_ke...
Race condition in the install_user_keyrings function in security/keys/process_keys.c in the Linux kernel before 3.8.3 allows local users to cause a denial of service (NULL pointer dereference and system crash) via crafted keyctl system calls that trigger keyring operations in simultaneous threads.
Scope: local
bookworm: resolved (fixed in 3.2.41-1)
bullseye: resolved (fixed in 3.2.41-1)
forky: resolved (fixed in 3.2.41-1)
sid: resolved (fixed in 3.2.41-1)
trixie: resolved (fixed in 3.2.41-1)
GHSA
GHSA-h378-c87p-mg3h: Race condition in the install_user_keyrings function in security/keys/process_keys
ghsa_unreviewed·2022-05-17
CVE-2013-1792 [MEDIUM] CWE-362 GHSA-h378-c87p-mg3h: Race condition in the install_user_keyrings function in security/keys/process_keys
Race condition in the install_user_keyrings function in security/keys/process_keys.c in the Linux kernel before 3.8.3 allows local users to cause a denial of service (NULL pointer dereference and system crash) via crafted keyctl system calls that trigger keyring operations in simultaneous threads.
OSV
CVE-2013-1792: Race condition in the install_user_keyrings function in security/keys/process_keys
osv·2013-03-22·CVSS 4.7
CVE-2013-1792 [MEDIUM] CVE-2013-1792: Race condition in the install_user_keyrings function in security/keys/process_keys
Race condition in the install_user_keyrings function in security/keys/process_keys.c in the Linux kernel before 3.8.3 allows local users to cause a denial of service (NULL pointer dereference and system crash) via crafted keyctl system calls that trigger keyring operations in simultaneous threads.
Kernel
keys: fix race with concurrent install_user_keyrings()
kernel_security·2013-03-12·CVSS 4.7
CVE-2013-1792 [MEDIUM] keys: fix race with concurrent install_user_keyrings()
keys: fix race with concurrent install_user_keyrings()
This fixes CVE-2013-1792.
There is a race in install_user_keyrings() that can cause a NULL pointer
dereference when called concurrently for the same user if the uid and
uid-session keyrings are not yet created. It might be possible for an
unprivileged user to trigger this by calling keyctl() from userspace in
parallel immediately after logging in.
Assume that we have two threads both executing lookup_user_key(), both
looking for KEY_SPEC_USER_SESSION_KEYRING.
THREAD A THREAD B
=============================== ===============================
==>call install_user_keyrings();
if (!cred->user->session_keyring)
==>call install_user_keyrings()
...
user->uid_keyring = uid_keyring;
if (user->uid_keyring)
return 0;
user->session_keyring [==
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2013-1792 Kernel: keys: race condition in install_user_keyrings() [fedora-all]
bugzilla·2013-03-07·CVSS 4.7
CVE-2013-1792 [MEDIUM] CVE-2013-1792 Kernel: keys: race condition in install_user_keyrings() [fedora-all]
CVE-2013-1792 Kernel: keys: race condition in install_user_keyrings() [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Please note: this issu
Bugzilla
CVE-2013-1792 Kernel: keys: race condition in install_user_keyrings()
bugzilla·2013-02-28·CVSS 4.7
CVE-2013-1792 [MEDIUM] CVE-2013-1792 Kernel: keys: race condition in install_user_keyrings()
CVE-2013-1792 Kernel: keys: race condition in install_user_keyrings()
A race condition leading to a NULL pointer dereference is discovered in the
Linux kernel. It occurs during parallel invocation of install_user_keyrings
& lookup_user_key routines.
An unprivileged user could use this flaw to crash the system, resulting in DoS.
Discussion:
Statement:
This issue does not affect the versions of the kernel package as shipped with Red Hat Enterprise Linux 5.
This issue affects the version of Linux kernel as shipped with Red Hat Enterprise Linux 6 and Red Hat Enterprise MRG 2. Future kernel updates for Red Hat Enterprise MRG 2 may address this issue.
---
Acknowledgements:
This issue was discovered by Mateusz Guzik of Red Hat EMEA GSS SEG Team.
---
Upstream fix:
-> https://lkml.org/lk
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=0da9dfdd2cd9889201bc6f6f43580c99165cd087http://lists.opensuse.org/opensuse-security-announce/2013-07/msg00018.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-02/msg00002.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0744.htmlhttp://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.8.3http://www.mandriva.com/security/advisories?name=MDVSA-2013:176http://www.openwall.com/lists/oss-security/2013/03/07/1http://www.ubuntu.com/usn/USN-1787-1http://www.ubuntu.com/usn/USN-1788-1http://www.ubuntu.com/usn/USN-1792-1http://www.ubuntu.com/usn/USN-1793-1http://www.ubuntu.com/usn/USN-1794-1http://www.ubuntu.com/usn/USN-1795-1http://www.ubuntu.com/usn/USN-1796-1http://www.ubuntu.com/usn/USN-1797-1http://www.ubuntu.com/usn/USN-1798-1https://bugzilla.redhat.com/show_bug.cgi?id=916646https://github.com/torvalds/linux/commit/0da9dfdd2cd9889201bc6f6f43580c99165cd087http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=0da9dfdd2cd9889201bc6f6f43580c99165cd087http://lists.opensuse.org/opensuse-security-announce/2013-07/msg00018.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-02/msg00002.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0744.htmlhttp://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.8.3http://www.mandriva.com/security/advisories?name=MDVSA-2013:176http://www.openwall.com/lists/oss-security/2013/03/07/1http://www.ubuntu.com/usn/USN-1787-1http://www.ubuntu.com/usn/USN-1788-1http://www.ubuntu.com/usn/USN-1792-1http://www.ubuntu.com/usn/USN-1793-1http://www.ubuntu.com/usn/USN-1794-1http://www.ubuntu.com/usn/USN-1795-1http://www.ubuntu.com/usn/USN-1796-1http://www.ubuntu.com/usn/USN-1797-1http://www.ubuntu.com/usn/USN-1798-1https://bugzilla.redhat.com/show_bug.cgi?id=916646https://github.com/torvalds/linux/commit/0da9dfdd2cd9889201bc6f6f43580c99165cd087
2013-03-22
Published