CVE-2015-7872
published 2015-11-16CVE-2015-7872: The key_gc_unused_keys function in security/keys/gc.c in the Linux kernel through 4.2.6 allows local users to cause a denial of service (OOPS) via crafted…
PriorityP49low2.1CVSS 2.0
AVLACLAuNCNINAP
EPSS
0.51%
40.9th percentile
The key_gc_unused_keys function in security/keys/gc.c in the Linux kernel through 4.2.6 allows local users to cause a denial of service (OOPS) via crafted keyctl commands.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 4.2.5-1 (bookworm) | linux 4.2.5-1 (bookworm) |
| android | — | — | |
| linux | linux_kernel | <= 4.2.6 | — |
| linux | linux_kernel | >= 0 < 4.2.5-1 | 4.2.5-1 |
| linux | linux_kernel | >= 0 < 4.2.5-1 | 4.2.5-1 |
| linux | linux_kernel | >= 0 < 4.2.5-1 | 4.2.5-1 |
| linux | linux_kernel | >= 0 < 4.2.5-1 | 4.2.5-1 |
| linux | linux_kernel | >= 0 < 3.13.0-71.114 | 3.13.0-71.114 |
CVSS provenance
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:N/I:N/A:P
osv4.9MEDIUM
vendor_ubuntu4.9MEDIUM
vendor_debian2.1LOW
vendor_redhat2.1LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-jvjc-3jqr-63px: The key_gc_unused_keys function in security/keys/gc
ghsa_unreviewed·2022-05-17
CVE-2015-7872 [LOW] CWE-20 GHSA-jvjc-3jqr-63px: The key_gc_unused_keys function in security/keys/gc
The key_gc_unused_keys function in security/keys/gc.c in the Linux kernel through 4.2.6 allows local users to cause a denial of service (OOPS) via crafted keyctl commands.
OSV
linux-lts-wily vulnerabilities
osv·2015-12-17·CVSS 4.9
CVE-2015-8104 [MEDIUM] linux-lts-wily vulnerabilities
linux-lts-wily vulnerabilities
Jan Beulich discovered that the KVM svm hypervisor implementation in the
Linux kernel did not properly catch Debug exceptions on AMD processors. An
attacker in a guest virtual machine could use this to cause a denial of
service (system crash) in the host OS. (CVE-2015-8104)
郭永刚 discovered that the ppp implementation in the Linux kernel did
not ensure that certain slot numbers are valid. A local attacker with the
privilege to call ioctl() on /dev/ppp could cause a denial of service
(system crash). (CVE-2015-7799)
Dmitry Vyukov discovered that the Linux kernel's keyring handler attempted
to garbage collect incompletely instantiated keys. A local unprivileged
attacker could use this to cause a denial of service (system crash).
(CVE-2015-7872)
It was discover
OSV
linux-lts-vivid vulnerabilities
osv·2015-12-04·CVSS 4.7
CVE-2015-5283 [MEDIUM] linux-lts-vivid vulnerabilities
linux-lts-vivid vulnerabilities
It was discovered that the SCTP protocol implementation in the Linux kernel
performed an incorrect sequence of protocol-initialization steps. A local
attacker could use this to cause a denial of service (system crash).
(CVE-2015-5283)
Dmitry Vyukov discovered that the Linux kernel's keyring handler attempted
to garbage collect incompletely instantiated keys. A local unprivileged
attacker could use this to cause a denial of service (system crash).
(CVE-2015-7872)
OSV
linux vulnerabilities
osv·2015-12-01·CVSS 4.7
CVE-2015-5283 [MEDIUM] linux vulnerabilities
linux vulnerabilities
It was discovered that the SCTP protocol implementation in the Linux kernel
performed an incorrect sequence of protocol-initialization steps. A local
attacker could use this to cause a denial of service (system crash).
(CVE-2015-5283)
Dmitry Vyukov discovered that the Linux kernel's keyring handler attempted
to garbage collect incompletely instantiated keys. A local unprivileged
attacker could use this to cause a denial of service (system crash).
(CVE-2015-7872)
OSV
CVE-2015-7872: The key_gc_unused_keys function in security/keys/gc
osv·2015-11-16·CVSS 2.1
CVE-2015-7872 [LOW] CVE-2015-7872: The key_gc_unused_keys function in security/keys/gc
The key_gc_unused_keys function in security/keys/gc.c in the Linux kernel through 4.2.6 allows local users to cause a denial of service (OOPS) via crafted keyctl commands.
Android
CVE-2015-7872: Android Security Bulletin 2016-12-01
CVE: CVE-2015-7872
Severity: HIGH
References: A-31253168
Upstream kernel
vendor_android·2016-12-01·CVSS 2.1
CVE-2015-7872 [LOW] CVE-2015-7872: Android Security Bulletin 2016-12-01
CVE: CVE-2015-7872
Severity: HIGH
References: A-31253168
Upstream kernel
Android Security Bulletin 2016-12-01
CVE: CVE-2015-7872
Severity: HIGH
References: A-31253168
Upstream kernel
Ubuntu
Linux kernel (Wily HWE) vulnerabilities
vendor_ubuntu·2015-12-17·CVSS 4.9
CVE-2015-7799 [MEDIUM] Linux kernel (Wily HWE) vulnerabilities
Title: Linux kernel (Wily HWE) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Jan Beulich discovered that the KVM svm hypervisor implementation in the
Linux kernel did not properly catch Debug exceptions on AMD processors. An
attacker in a guest virtual machine could use this to cause a denial of
service (system crash) in the host OS. (CVE-2015-8104)
郭永刚 discovered that the ppp implementation in the Linux kernel did
not ensure that certain slot numbers are valid. A local attacker with the
privilege to call ioctl() on /dev/ppp could cause a denial of service
(system crash). (CVE-2015-7799)
Dmitry Vyukov discovered that the Linux kernel's keyring handler attempted
to garbage collect incompletely instantiated keys. A local unprivileged
attacker could use this t
Ubuntu
Linux kernel (OMAP4) vulnerability
vendor_ubuntu·2015-12-17
CVE-2015-7872 Linux kernel (OMAP4) vulnerability
Title: Linux kernel (OMAP4) vulnerability
Summary: The system could be made to crash under certain conditions.
Dmitry Vyukov discovered that the Linux kernel's keyring handler attempted
to garbage collect incompletely instantiated keys. A local unprivileged
attacker could use this to cause a denial of service (system crash).
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed. If
you use linux-restricted-modules, you have to update that package as
well to get modules which work with the new kernel version. Unless you
manually
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2015-12-17·CVSS 4.9
CVE-2015-7799 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
Jan Beulich discovered that the KVM svm hypervisor implementation in the
Linux kernel did not properly catch Debug exceptions on AMD processors. An
attacker in a guest virtual machine could use this to cause a denial of
service (system crash) in the host OS. (CVE-2015-8104)
郭永刚 discovered that the ppp implementation in the Linux kernel did
not ensure that certain slot numbers are valid. A local attacker with the
privilege to call ioctl() on /dev/ppp could cause a denial of service
(system crash). (CVE-2015-7799)
Dmitry Vyukov discovered that the Linux kernel's keyring handler attempted
to garbage collect incompletely instantiated keys. A local unprivileged
attacker could use this to cause a d
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2015-12-17·CVSS 2.1
CVE-2015-7872 [LOW] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
Dmitry Vyukov discovered that the Linux kernel's keyring handler attempted
to garbage collect incompletely instantiated keys. A local unprivileged
attacker could use this to cause a denial of service (system crash).
(CVE-2015-7872)
Jan Beulich discovered that the KVM svm hypervisor implementation in the
Linux kernel did not properly catch Debug exceptions on AMD processors. An
attacker in a guest virtual machine could use this to cause a denial of
service (system crash) in the host OS. (CVE-2015-8104)
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a
Ubuntu
Linux kernel (Vivid HWE) vulnerabilities
vendor_ubuntu·2015-12-04·CVSS 4.7
CVE-2015-5283 [MEDIUM] Linux kernel (Vivid HWE) vulnerabilities
Title: Linux kernel (Vivid HWE) vulnerabilities
Summary: Several security issues were fixed in the kernel.
It was discovered that the SCTP protocol implementation in the Linux kernel
performed an incorrect sequence of protocol-initialization steps. A local
attacker could use this to cause a denial of service (system crash).
(CVE-2015-5283)
Dmitry Vyukov discovered that the Linux kernel's keyring handler attempted
to garbage collect incompletely instantiated keys. A local unprivileged
attacker could use this to cause a denial of service (system crash).
(CVE-2015-7872)
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which r
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2015-12-04·CVSS 4.7
CVE-2015-5283 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
It was discovered that the SCTP protocol implementation in the Linux kernel
performed an incorrect sequence of protocol-initialization steps. A local
attacker could use this to cause a denial of service (system crash).
(CVE-2015-5283)
Dmitry Vyukov discovered that the Linux kernel's keyring handler attempted
to garbage collect incompletely instantiated keys. A local unprivileged
attacker could use this to cause a denial of service (system crash).
(CVE-2015-7872)
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you
Ubuntu
Linux kernel (Trusty HWE) vulnerabilities
vendor_ubuntu·2015-12-03·CVSS 4.7
CVE-2015-5283 [MEDIUM] Linux kernel (Trusty HWE) vulnerabilities
Title: Linux kernel (Trusty HWE) vulnerabilities
Summary: Several security issues were fixed in the kernel.
It was discovered that the SCTP protocol implementation in the Linux kernel
performed an incorrect sequence of protocol-initialization steps. A local
attacker could use this to cause a denial of service (system crash).
(CVE-2015-5283)
Dmitry Vyukov discovered that the Linux kernel's keyring handler attempted
to garbage collect incompletely instantiated keys. A local unprivileged
attacker could use this to cause a denial of service (system crash).
(CVE-2015-7872)
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which
Ubuntu
Linux kernel (Utopic HWE) vulnerability
vendor_ubuntu·2015-12-01
CVE-2015-7872 Linux kernel (Utopic HWE) vulnerability
Title: Linux kernel (Utopic HWE) vulnerability
Summary: The system could be made to crash under certain conditions.
Dmitry Vyukov discovered that the Linux kernel's keyring handler attempted
to garbage collect incompletely instantiated keys. A local unprivileged
attacker could use this to cause a denial of service (system crash).
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed. If
you use linux-restricted-modules, you have to update that package as
well to get modules which work with the new kernel version. Unless you
manu
Red Hat
kernel: Keyrings crash triggerable by unprivileged user
vendor_redhat·2015-10-12·CVSS 2.1
CVE-2015-7872 [LOW] CWE-456 kernel: Keyrings crash triggerable by unprivileged user
kernel: Keyrings crash triggerable by unprivileged user
The key_gc_unused_keys function in security/keys/gc.c in the Linux kernel through 4.2.6 allows local users to cause a denial of service (OOPS) via crafted keyctl commands.
It was found that the Linux kernel's keys subsystem did not correctly garbage collect uninstantiated keyrings. A local attacker could use this flaw to crash the system or, potentially, escalate their privileges on the system.
Statement: This issue affects the Linux kernels as shipped with Red Hat Enterprise Linux 6 , 7 and Red Hat MRG 2. Future updates for the respective releases may address this flaw.
Package: kernel (Red Hat Enterprise Linux 5) - Not affected
Debian
CVE-2015-7872: linux - The key_gc_unused_keys function in security/keys/gc.c in the Linux kernel throug...
vendor_debian·2015·CVSS 2.1
CVE-2015-7872 [LOW] CVE-2015-7872: linux - The key_gc_unused_keys function in security/keys/gc.c in the Linux kernel throug...
The key_gc_unused_keys function in security/keys/gc.c in the Linux kernel through 4.2.6 allows local users to cause a denial of service (OOPS) via crafted keyctl commands.
Scope: local
bookworm: resolved (fixed in 4.2.5-1)
bullseye: resolved (fixed in 4.2.5-1)
forky: resolved (fixed in 4.2.5-1)
sid: resolved (fixed in 4.2.5-1)
trixie: resolved (fixed in 4.2.5-1)
No detection rules found.
No public exploits indexed.
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=ce1fad2740c648a4340f6f6c391a8a83769d2e8chttp://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=f05819df10d7b09f6d1eb6f8534a8f68e5a4fe61http://lists.opensuse.org/opensuse-security-announce/2015-11/msg00035.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-12/msg00005.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-12/msg00018.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-12/msg00026.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-12/msg00031.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-02/msg00007.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-02/msg00009.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-02/msg00013.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-02/msg00017.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-02/msg00018.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-02/msg00019.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-02/msg00020.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-02/msg00021.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-02/msg00022.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-02/msg00034.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-04/msg00015.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-08/msg00038.htmlhttp://marc.info/?l=bugtraq&m=145975164525836&w=2http://rhn.redhat.com/errata/RHSA-2015-2636.htmlhttp://rhn.redhat.com/errata/RHSA-2016-0185.htmlhttp://rhn.redhat.com/errata/RHSA-2016-0212.htmlhttp://rhn.redhat.com/errata/RHSA-2016-0224.htmlhttp://www.debian.org/security/2015/dsa-3396http://www.openwall.com/lists/oss-security/2015/10/20/6http://www.oracle.com/technetwork/topics/security/linuxbulletinjan2016-2867209.htmlhttp://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.htmlhttp://www.securityfocus.com/bid/77544http://www.securitytracker.com/id/1034472http://www.ubuntu.com/usn/USN-2823-1http://www.ubuntu.com/usn/USN-2824-1http://www.ubuntu.com/usn/USN-2826-1http://www.ubuntu.com/usn/USN-2829-1http://www.ubuntu.com/usn/USN-2829-2http://www.ubuntu.com/usn/USN-2840-1http://www.ubuntu.com/usn/USN-2840-2http://www.ubuntu.com/usn/USN-2843-1http://www.ubuntu.com/usn/USN-2843-2http://www.ubuntu.com/usn/USN-2843-3https://bugzilla.redhat.com/show_bug.cgi?id=1272172https://bugzilla.redhat.com/show_bug.cgi?id=1272371https://github.com/torvalds/linux/commit/ce1fad2740c648a4340f6f6c391a8a83769d2e8chttps://github.com/torvalds/linux/commit/f05819df10d7b09f6d1eb6f8534a8f68e5a4fe61https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05068676https://source.android.com/security/bulletin/2016-12-01.htmlhttp://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=ce1fad2740c648a4340f6f6c391a8a83769d2e8chttp://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=f05819df10d7b09f6d1eb6f8534a8f68e5a4fe61http://lists.opensuse.org/opensuse-security-announce/2015-11/msg00035.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-12/msg00005.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-12/msg00018.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-12/msg00026.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-12/msg00031.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-02/msg00007.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-02/msg00009.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-02/msg00013.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-02/msg00017.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-02/msg00018.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-02/msg00019.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-02/msg00020.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-02/msg00021.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-02/msg00022.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-02/msg00034.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-04/msg00015.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-08/msg00038.htmlhttp://marc.info/?l=bugtraq&m=145975164525836&w=2http://rhn.redhat.com/errata/RHSA-2015-2636.htmlhttp://rhn.redhat.com/errata/RHSA-2016-0185.htmlhttp://rhn.redhat.com/errata/RHSA-2016-0212.htmlhttp://rhn.redhat.com/errata/RHSA-2016-0224.htmlhttp://www.debian.org/security/2015/dsa-3396http://www.openwall.com/lists/oss-security/2015/10/20/6http://www.oracle.com/technetwork/topics/security/linuxbulletinjan2016-2867209.htmlhttp://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.htmlhttp://www.securityfocus.com/bid/77544http://www.securitytracker.com/id/1034472http://www.ubuntu.com/usn/USN-2823-1http://www.ubuntu.com/usn/USN-2824-1http://www.ubuntu.com/usn/USN-2826-1http://www.ubuntu.com/usn/USN-2829-1http://www.ubuntu.com/usn/USN-2829-2http://www.ubuntu.com/usn/USN-2840-1http://www.ubuntu.com/usn/USN-2840-2http://www.ubuntu.com/usn/USN-2843-1http://www.ubuntu.com/usn/USN-2843-2http://www.ubuntu.com/usn/USN-2843-3https://bugzilla.redhat.com/show_bug.cgi?id=1272172https://bugzilla.redhat.com/show_bug.cgi?id=1272371https://github.com/torvalds/linux/commit/ce1fad2740c648a4340f6f6c391a8a83769d2e8chttps://github.com/torvalds/linux/commit/f05819df10d7b09f6d1eb6f8534a8f68e5a4fe61https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05068676https://source.android.com/security/bulletin/2016-12-01.html
2015-11-16
Published