CVE-2015-1333
published 2015-08-31CVE-2015-1333: Memory leak in the __key_link_end function in security/keys/keyring.c in the Linux kernel before 4.1.4 allows local users to cause a denial of service (memory…
PriorityP414medium4.9CVSS 2.0
AVLACLAuNCNINAC
EPSS
0.48%
39.2th percentile
Memory leak in the __key_link_end function in security/keys/keyring.c in the Linux kernel before 4.1.4 allows local users to cause a denial of service (memory consumption) via many add_key system calls that refer to existing keys.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 4.1.3-1 (bookworm) | linux 4.1.3-1 (bookworm) |
| djangoproject | django | >= 1.8a1 < 1.8.3 | 1.8.3 |
| linux | linux_kernel | <= 4.1.3 | — |
| linux | linux_kernel | >= 0 < 4.1.3-1 | 4.1.3-1 |
| linux | linux_kernel | >= 0 < 4.1.3-1 | 4.1.3-1 |
| linux | linux_kernel | >= 0 < 4.1.3-1 | 4.1.3-1 |
| linux | linux_kernel | >= 0 < 4.1.3-1 | 4.1.3-1 |
| linux | linux_kernel | >= 0 < 3.13.0-59.98 | 3.13.0-59.98 |
| markdown-it_project | markdown-it | >= 0 < 3.0.0 | 3.0.0 |
| marked_project | marked | >= 0 < 0.3.4 | 0.3.4 |
| npmjs | semver | >= 1.0.4 < 4.3.2 | 4.3.2 |
| vercel | ms | >= 0 < 0.7.1 | 0.7.1 |
CVSS provenance
nvdv2.04.9MEDIUMAV:L/AC:L/Au:N/C:N/I:N/A:C
osv4.9MEDIUM
vendor_redhat6.8MEDIUM
vendor_debian4.9MEDIUM
vendor_ubuntu4.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Linux kernel (Trusty HWE) vulnerabilities
vendor_ubuntu·2015-07-28·CVSS 4.9
CVE-2015-1333 [MEDIUM] Linux kernel (Trusty HWE) vulnerabilities
Title: Linux kernel (Trusty HWE) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Andy Lutomirski discovered a flaw in the Linux kernel's handling of nested
NMIs (non-maskable interrupts). An unprivileged local user could exploit
this flaw to cause a denial of service (system crash) or potentially
escalate their privileges. (CVE-2015-3290)
Colin King discovered a flaw in the add_key function of the Linux kernel's
keyring subsystem. A local user could exploit this flaw to cause a denial
of service (memory exhaustion). (CVE-2015-1333)
Andy Lutomirski discovered a flaw that allows user to cause the Linux
kernel to ignore some NMIs (non-maskable interrupts). A local unprivileged
user could exploit this flaw to potentially cause the system to miss
important NMIs re
Ubuntu
Linux kernel (Vivid HWE) vulnerabilities
vendor_ubuntu·2015-07-28·CVSS 4.9
CVE-2015-1333 [MEDIUM] Linux kernel (Vivid HWE) vulnerabilities
Title: Linux kernel (Vivid HWE) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Andy Lutomirski discovered a flaw in the Linux kernel's handling of nested
NMIs (non-maskable interrupts). An unprivileged local user could exploit
this flaw to cause a denial of service (system crash) or potentially
escalate their privileges. (CVE-2015-3290)
Colin King discovered a flaw in the add_key function of the Linux kernel's
keyring subsystem. A local user could exploit this flaw to cause a denial
of service (memory exhaustion). (CVE-2015-1333)
Andy Lutomirski discovered a flaw that allows user to cause the Linux
kernel to ignore some NMIs (non-maskable interrupts). A local unprivileged
user could exploit this flaw to potentially cause the system to miss
important NMIs res
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2015-07-28·CVSS 4.9
CVE-2015-1333 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
Andy Lutomirski discovered a flaw in the Linux kernel's handling of nested
NMIs (non-maskable interrupts). An unprivileged local user could exploit
this flaw to cause a denial of service (system crash) or potentially
escalate their privileges. (CVE-2015-3290)
Colin King discovered a flaw in the add_key function of the Linux kernel's
keyring subsystem. A local user could exploit this flaw to cause a denial
of service (memory exhaustion). (CVE-2015-1333)
Andy Lutomirski discovered a flaw that allows user to cause the Linux
kernel to ignore some NMIs (non-maskable interrupts). A local unprivileged
user could exploit this flaw to potentially cause the system to miss
important NMIs resulting in un
Ubuntu
Linux kernel (Utopic HWE) vulnerabilities
vendor_ubuntu·2015-07-28·CVSS 4.9
CVE-2015-1333 [MEDIUM] Linux kernel (Utopic HWE) vulnerabilities
Title: Linux kernel (Utopic HWE) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Andy Lutomirski discovered a flaw in the Linux kernel's handling of nested
NMIs (non-maskable interrupts). An unprivileged local user could exploit
this flaw to cause a denial of service (system crash) or potentially
escalate their privileges. (CVE-2015-3290)
Colin King discovered a flaw in the add_key function of the Linux kernel's
keyring subsystem. A local user could exploit this flaw to cause a denial
of service (memory exhaustion). (CVE-2015-1333)
Andy Lutomirski discovered a flaw that allows user to cause the Linux
kernel to ignore some NMIs (non-maskable interrupts). A local unprivileged
user could exploit this flaw to potentially cause the system to miss
important NMIs re
Red Hat
kernel: denial of service due to memory leak in add_key()
vendor_redhat·2015-07-27·CVSS 4.9
CVE-2015-1333 [MEDIUM] CWE-401 kernel: denial of service due to memory leak in add_key()
kernel: denial of service due to memory leak in add_key()
Memory leak in the __key_link_end function in security/keys/keyring.c in the Linux kernel before 4.1.4 allows local users to cause a denial of service (memory consumption) via many add_key system calls that refer to existing keys.
It was found that the Linux kernel's keyring implementation would leak memory when adding a key to a keyring via the add_key() function. A local attacker could use this flaw to exhaust all available memory on the system.
Statement: This issue does not affect the Linux kernel packages as shipped with Red Hat Enterprise Linux 5 and 6.
Package: kernel (Red Hat Enterprise Linux 5) - Not affected
Package: kernel (Red Hat Enterprise Linux 6) - Not affected
Red Hat
webkitgtk: arbitrary code execution and denial of service via a crafted web site (WSA-2015-0001)
vendor_redhat·2015-01-26·CVSS 6.8
CVE-2014-1333 [MEDIUM] webkitgtk: arbitrary code execution and denial of service via a crafted web site (WSA-2015-0001)
webkitgtk: arbitrary code execution and denial of service via a crafted web site (WSA-2015-0001)
WebKit, as used in Apple Safari before 6.1.4 and 7.x before 7.0.4, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2014-05-21-1.
Statement: Red Hat Product Security has rated this issue as having Moderate security impact. This issue is not currently planned to be addressed in future updates. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.
Package: webkitgtk (Red Hat Enterprise Linux 6) - Will not fix
Package: webkitgtk3 (Red Hat Enterprise Linux
Debian
CVE-2015-1333: linux - Memory leak in the __key_link_end function in security/keys/keyring.c in the Lin...
vendor_debian·2015·CVSS 4.9
CVE-2015-1333 [MEDIUM] CVE-2015-1333: linux - Memory leak in the __key_link_end function in security/keys/keyring.c in the Lin...
Memory leak in the __key_link_end function in security/keys/keyring.c in the Linux kernel before 4.1.4 allows local users to cause a denial of service (memory consumption) via many add_key system calls that refer to existing keys.
Scope: local
bookworm: resolved (fixed in 4.1.3-1)
bullseye: resolved (fixed in 4.1.3-1)
forky: resolved (fixed in 4.1.3-1)
sid: resolved (fixed in 4.1.3-1)
trixie: resolved (fixed in 4.1.3-1)
GHSA
markdown-it vulnerable to Inefficient Regular Expression Complexity
ghsa·2022-12-27
CVE-2015-10005 [HIGH] CWE-1333 markdown-it vulnerable to Inefficient Regular Expression Complexity
markdown-it vulnerable to Inefficient Regular Expression Complexity
A vulnerability was found in markdown-it up to 2.x. It has been classified as problematic. Affected is an unknown function of the file `lib/common/html_re.js`. The manipulation leads to inefficient regular expression complexity. Upgrading to version 3.0.0 is able to address this issue. The name of the patch is 89c8620157d6e38f9872811620d25138fc9d1b0d. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-216852.
GHSA
Django ReDoS in validators.URLValidator
ghsa·2022-05-17
CVE-2015-5145 [HIGH] CWE-1333 Django ReDoS in validators.URLValidator
Django ReDoS in validators.URLValidator
`validators.URLValidator` in Django 1.8.x before 1.8.3 allows remote attackers to cause a denial of service (CPU consumption) via unspecified vectors.
GHSA
GHSA-wwgx-5rpw-xwxw: Memory leak in the __key_link_end function in security/keys/keyring
ghsa_unreviewed·2022-05-14
CVE-2015-1333 [MEDIUM] CWE-119 GHSA-wwgx-5rpw-xwxw: Memory leak in the __key_link_end function in security/keys/keyring
Memory leak in the __key_link_end function in security/keys/keyring.c in the Linux kernel before 4.1.4 allows local users to cause a denial of service (memory consumption) via many add_key system calls that refer to existing keys.
GHSA
Regular Expression Denial of Service in marked
ghsa·2017-10-24
CVE-2015-8854 [HIGH] CWE-1333 Regular Expression Denial of Service in marked
Regular Expression Denial of Service in marked
Versions 0.3.3 and earlier of `marked` are affected by a regular expression denial of service ( ReDoS ) vulnerability when passed inputs that reach the `em` inline rule.
## Recommendation
Update to version 0.3.4 or later.
GHSA
Regular Expression Denial of Service in semver
ghsa·2017-10-24
CVE-2015-8855 [HIGH] CWE-1333 Regular Expression Denial of Service in semver
Regular Expression Denial of Service in semver
Versions 4.3.1 and earlier of `semver` are affected by a regular expression denial of service vulnerability when extremely long version strings are parsed.
## Recommendation
Update to version 4.3.2 or later
GHSA
Regular Expression Denial of Service in ms
ghsa·2017-10-24
CVE-2015-8315 [HIGH] CWE-1333 Regular Expression Denial of Service in ms
Regular Expression Denial of Service in ms
Versions of `ms` prior to 0.7.1 are affected by a regular expression denial of service vulnerability when extremely long version strings are parsed.
## Proof of Concept
```javascript
var ms = require('ms');
var genstr = function (len, chr) {
var result = "";
for (i=0; i<=len; i++) {
result = result + chr;
}
return result;
}
ms(genstr(process.argv[2], "5") + " minutea");
```
### Results
Showing increase in execution time based on the input string.
```
$ time node ms.js 10000
real 0m0.758s
user 0m0.724s
sys 0m0.031s
$ time node ms.js 20000
real 0m2.580s
user 0m2.494s
sys 0m0.047s
$ time node ms.js 30000
real 0m5.747s
user 0m5.483s
sys 0m0.080s
$ time node ms.js 80000
real 0m41.022s
user 0m38.894s
sys 0m0.529s
```
GHSA
Regular Expression Denial of Service in uglify-js
ghsa·2017-10-24
CVE-2015-8858 [HIGH] CWE-1333 Regular Expression Denial of Service in uglify-js
Regular Expression Denial of Service in uglify-js
Versions of `uglify-js` prior to 2.6.0 are affected by a regular expression denial of service vulnerability when malicious inputs are passed into the `parse()` method.
### Proof of Concept
```
var u = require('uglify-js');
var genstr = function (len, chr) {
var result = "";
for (i=0; i<=len; i++) {
result = result + chr;
}
return result;
}
u.parse("var a = " + genstr(process.argv[2], "1") + ".1ee7;");
```
### Results
```
$ time node test.js 10000
real 0m1.091s
user 0m1.047s
sys 0m0.039s
$ time node test.js 80000
real 0m6.486s
user 0m6.229s
sys 0m0.094s
```
## Recommendation
Update to version 2.6.0 or later.
OSV
CVE-2015-1333: Memory leak in the __key_link_end function in security/keys/keyring
osv·2015-08-31·CVSS 4.9
CVE-2015-1333 [MEDIUM] CVE-2015-1333: Memory leak in the __key_link_end function in security/keys/keyring
Memory leak in the __key_link_end function in security/keys/keyring.c in the Linux kernel before 4.1.4 allows local users to cause a denial of service (memory consumption) via many add_key system calls that refer to existing keys.
OSV
linux-lts-utopic vulnerabilities
osv·2015-07-28·CVSS 4.9
CVE-2015-3290 [MEDIUM] linux-lts-utopic vulnerabilities
linux-lts-utopic vulnerabilities
Andy Lutomirski discovered a flaw in the Linux kernel's handling of nested
NMIs (non-maskable interrupts). An unprivileged local user could exploit
this flaw to cause a denial of service (system crash) or potentially
escalate their privileges. (CVE-2015-3290)
Colin King discovered a flaw in the add_key function of the Linux kernel's
keyring subsystem. A local user could exploit this flaw to cause a denial
of service (memory exhaustion). (CVE-2015-1333)
Andy Lutomirski discovered a flaw that allows user to cause the Linux
kernel to ignore some NMIs (non-maskable interrupts). A local unprivileged
user could exploit this flaw to potentially cause the system to miss
important NMIs resulting in unspecified effects. (CVE-2015-3291)
Andy Lutomirski and Petr Ma
OSV
linux-lts-vivid vulnerabilities
osv·2015-07-28·CVSS 4.9
CVE-2015-3290 [MEDIUM] linux-lts-vivid vulnerabilities
linux-lts-vivid vulnerabilities
Andy Lutomirski discovered a flaw in the Linux kernel's handling of nested
NMIs (non-maskable interrupts). An unprivileged local user could exploit
this flaw to cause a denial of service (system crash) or potentially
escalate their privileges. (CVE-2015-3290)
Colin King discovered a flaw in the add_key function of the Linux kernel's
keyring subsystem. A local user could exploit this flaw to cause a denial
of service (memory exhaustion). (CVE-2015-1333)
Andy Lutomirski discovered a flaw that allows user to cause the Linux
kernel to ignore some NMIs (non-maskable interrupts). A local unprivileged
user could exploit this flaw to potentially cause the system to miss
important NMIs resulting in unspecified effects. (CVE-2015-3291)
Andy Lutomirski and Petr Mat
OSV
linux vulnerabilities
osv·2015-07-28·CVSS 4.9
CVE-2015-3290 [MEDIUM] linux vulnerabilities
linux vulnerabilities
Andy Lutomirski discovered a flaw in the Linux kernel's handling of nested
NMIs (non-maskable interrupts). An unprivileged local user could exploit
this flaw to cause a denial of service (system crash) or potentially
escalate their privileges. (CVE-2015-3290)
Colin King discovered a flaw in the add_key function of the Linux kernel's
keyring subsystem. A local user could exploit this flaw to cause a denial
of service (memory exhaustion). (CVE-2015-1333)
Andy Lutomirski discovered a flaw that allows user to cause the Linux
kernel to ignore some NMIs (non-maskable interrupts). A local unprivileged
user could exploit this flaw to potentially cause the system to miss
important NMIs resulting in unspecified effects. (CVE-2015-3291)
Andy Lutomirski and Petr Matousek disc
Kernel
KEYS: ensure we free the assoc array edit if edit is valid
kernel_security·2015-07-27·CVSS 4.9
CVE-2015-1333 [MEDIUM] KEYS: ensure we free the assoc array edit if edit is valid
KEYS: ensure we free the assoc array edit if edit is valid
__key_link_end is not freeing the associated array edit structure
and this leads to a 512 byte memory leak each time an identical
existing key is added with add_key().
The reason the add_key() system call returns okay is that
key_create_or_update() calls __key_link_begin() before checking to see
whether it can update a key directly rather than adding/replacing - which
it turns out it can. Thus __key_link() is not called through
__key_instantiate_and_link() and __key_link_end() must cancel the edit.
CVE-2015-1333
Signed-off-by: Colin Ian King
Signed-off-by: David Howells
Signed-off-by: James Morris
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-1333 kernel: denial of service due to memory leak in add_key()
bugzilla·2015-07-22·CVSS 4.9
CVE-2015-1333 [MEDIUM] CVE-2015-1333 kernel: denial of service due to memory leak in add_key()
CVE-2015-1333 kernel: denial of service due to memory leak in add_key()
It was reported that it's possible for any user to run the kernel out of memory through a memory leak in add_key().
Acknowledgements:
Red Hat would like to thank Canonical for reporting this issue.
Discussion:
Created attachment 1054857
CVE-2015-1333.patch
---
Statement:
This issue does not affect the Linux kernel packages as shipped with Red Hat Enterprise Linux 5 and 6.
---
References:
http://www.openwall.com/lists/oss-security/2015/07/27/7
---
This issue has been addressed in the following products:
MRG for RHEL-6 v.2
Via RHSA-2015:1787 https://rhn.redhat.com/errata/RHSA-2015-1787.html
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2015:1788 https:
Bugzilla
CVE-2014-1333 webkitgtk: arbitrary code execution and denial of service via a crafted web site (WSA-2015-0001)
bugzilla·2015-01-27·CVSS 6.8
CVE-2014-1333 [MEDIUM] CVE-2014-1333 webkitgtk: arbitrary code execution and denial of service via a crafted web site (WSA-2015-0001)
CVE-2014-1333 webkitgtk: arbitrary code execution and denial of service via a crafted web site (WSA-2015-0001)
Following vulnerability was discovered on the 2.4 stable series of WebKitGTK+:
CVE-2014-1333
WebKit, as used in Apple Safari before 6.1.4 and 7.x before 7.0.4, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2014-05-21-1.
External References:
http://webkitgtk.org/security/WSA-2015-0001.html
Discussion:
Statement:
Red Hat Product Security has rated this issue as having Moderate security impact. This issue is not currently planned to be addressed in future updates. For additional information, refer to the Issue Se
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=ca4da5dd1f99fe9c59f1709fb43e818b18ad20e0http://rhn.redhat.com/errata/RHSA-2015-1778.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1787.htmlhttp://www.debian.org/security/2015/dsa-3329http://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.1.4http://www.openwall.com/lists/oss-security/2015/07/27/7http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.htmlhttp://www.securityfocus.com/bid/76050http://www.ubuntu.com/usn/USN-2687-1http://www.ubuntu.com/usn/USN-2688-1http://www.ubuntu.com/usn/USN-2689-1http://www.ubuntu.com/usn/USN-2690-1http://www.ubuntu.com/usn/USN-2691-1https://bugzilla.redhat.com/show_bug.cgi?id=1245658https://github.com/torvalds/linux/commit/ca4da5dd1f99fe9c59f1709fb43e818b18ad20e0https://support.f5.com/csp/article/K05211147http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=ca4da5dd1f99fe9c59f1709fb43e818b18ad20e0http://rhn.redhat.com/errata/RHSA-2015-1778.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1787.htmlhttp://www.debian.org/security/2015/dsa-3329http://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.1.4http://www.openwall.com/lists/oss-security/2015/07/27/7http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.htmlhttp://www.securityfocus.com/bid/76050http://www.ubuntu.com/usn/USN-2687-1http://www.ubuntu.com/usn/USN-2688-1http://www.ubuntu.com/usn/USN-2689-1http://www.ubuntu.com/usn/USN-2690-1http://www.ubuntu.com/usn/USN-2691-1https://bugzilla.redhat.com/show_bug.cgi?id=1245658https://github.com/torvalds/linux/commit/ca4da5dd1f99fe9c59f1709fb43e818b18ad20e0https://support.f5.com/csp/article/K05211147
2015-08-31
Published