cbcvebase.
CVE-2016-4470
published 2016-06-27

CVE-2016-4470: The key_reject_and_link function in security/keys/key.c in the Linux kernel through 4.6.3 does not ensure that a certain data structure is initialized, which…

medium5.5CVSS 3.0
AVLACLPRLUINSUCNINAH
The key_reject_and_link function in security/keys/key.c in the Linux kernel through 4.6.3 does not ensure that a certain data structure is initialized, which allows local users to cause a denial of service (system crash) via vectors involving a crafted keyctl request2 command.

Affected

25 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 4.6.2-2 (bookworm)linux 4.6.2-2 (bookworm)
googleandroid
linuxlinux_kernel<= 4.6.3
linuxlinux_kernel>= 0 < 4.6.2-24.6.2-2
linuxlinux_kernel>= 0 < 4.6.2-24.6.2-2
linuxlinux_kernel>= 0 < 4.6.2-24.6.2-2
linuxlinux_kernel>= 0 < 4.6.2-24.6.2-2
linuxlinux_kernel>= 0 < 3.13.0-93.1403.13.0-93.140
linuxlinux_kernel>= 0 < 4.4.0-34.534.4.0-34.53
novellsuse_linux_enterprise_real_time_extension
oraclelinux
oraclelinux
oraclelinux
oraclevm_server
oraclevm_server
redhatenterprise_linux
redhatenterprise_linux_desktop
redhatenterprise_linux_for_real_time
redhatenterprise_linux_hpc_node
redhatenterprise_linux_hpc_node_eus
redhatenterprise_linux_server
redhatenterprise_linux_server_aus
redhatenterprise_linux_server_eus
redhatenterprise_linux_workstation
redhatenterprise_mrg

CVSS provenance

nvdv3.05.5MEDIUMCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv7.8HIGH