CVE-2016-8650
published 2016-11-28CVE-2016-8650: The mpi_powm function in lib/mpi/mpi-pow.c in the Linux kernel through 4.8.11 does not ensure that memory is allocated for limb data, which allows local users…
PriorityP420medium5.5CVSS 3.0
AVLACLPRLUINSUCNINAH
EPSS
0.41%
33.4th percentile
The mpi_powm function in lib/mpi/mpi-pow.c in the Linux kernel through 4.8.11 does not ensure that memory is allocated for limb data, which allows local users to cause a denial of service (stack memory corruption and panic) via an add_key system call for an RSA key with a zero exponent.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 4.8.11-1 (bookworm) | linux 4.8.11-1 (bookworm) |
| android | — | — | |
| linux | linux_kernel | <= 4.8.11 | — |
| linux | linux_kernel | >= 0 < 4.8.11-1 | 4.8.11-1 |
| linux | linux_kernel | >= 0 < 4.8.11-1 | 4.8.11-1 |
| linux | linux_kernel | >= 0 < 4.8.11-1 | 4.8.11-1 |
| linux | linux_kernel | >= 0 < 4.8.11-1 | 4.8.11-1 |
| linux | linux_kernel | >= 0 < 3.13.0-132.181 | 3.13.0-132.181 |
CVSS provenance
nvdv3.05.5MEDIUMCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv2.04.9MEDIUMAV:L/AC:L/Au:N/C:N/I:N/A:C
osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2017-09-18·CVSS 7.8
CVE-2016-10044 [HIGH] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
It was discovered that a buffer overflow existed in the Bluetooth stack of
the Linux kernel when handling L2CAP configuration responses. A physically
proximate attacker could use this to cause a denial of service (system
crash). (CVE-2017-1000251)
It was discovered that the asynchronous I/O (aio) subsystem of the Linux
kernel did not properly set permissions on aio memory mappings in some
situations. An attacker could use this to more easily exploit other
vulnerabilities. (CVE-2016-10044)
Baozeng Ding and Andrey Konovalov discovered a race condition in the L2TPv3
IP Encapsulation implementation in the Linux kernel. A local attacker could
use this to cause a denial of service (system cra
Ubuntu
Linux kernel (Trusty HWE) vulnerabilities
vendor_ubuntu·2017-09-18·CVSS 7.8
CVE-2016-10044 [HIGH] Linux kernel (Trusty HWE) vulnerabilities
Title: Linux kernel (Trusty HWE) vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
USN-3422-1 fixed vulnerabilities in the Linux kernel for Ubuntu 14.04
LTS. This update provides the corresponding updates for the Linux
Hardware Enablement (HWE) kernel from Ubuntu 14.04 LTS for Ubuntu
12.04 LTS.
It was discovered that a buffer overflow existed in the Bluetooth stack of
the Linux kernel when handling L2CAP configuration responses. A physically
proximate attacker could use this to cause a denial of service (system
crash). (CVE-2017-1000251)
It was discovered that the asynchronous I/O (aio) subsystem of the Linux
kernel did not properly set permissions on aio memory mappings in some
situations. An attacker could use this to more easily exploit other
vulnerabi
Android
CVE-2016-8650: Android Security Bulletin 2017-03-01
CVE: CVE-2016-8650
Severity: HIGH
References: A-33401771
Upstream kernel
vendor_android·2017-03-01·CVSS 5.5
CVE-2016-8650 [MEDIUM] CVE-2016-8650: Android Security Bulletin 2017-03-01
CVE: CVE-2016-8650
Severity: HIGH
References: A-33401771
Upstream kernel
Android Security Bulletin 2017-03-01
CVE: CVE-2016-8650
Severity: HIGH
References: A-33401771
Upstream kernel
Red Hat
kernel: Null pointer dereference via keyctl
vendor_redhat·2016-11-15·CVSS 5.5
CVE-2016-8650 [MEDIUM] CWE-476 kernel: Null pointer dereference via keyctl
kernel: Null pointer dereference via keyctl
The mpi_powm function in lib/mpi/mpi-pow.c in the Linux kernel through 4.8.11 does not ensure that memory is allocated for limb data, which allows local users to cause a denial of service (stack memory corruption and panic) via an add_key system call for an RSA key with a zero exponent.
A flaw was found in the Linux kernel key management subsystem in which a local attacker could crash the kernel or corrupt the stack and additional memory (denial of service) by supplying a specially crafted RSA key. This flaw panics the machine during the verification of the RSA key.
Statement: This issue affects the Linux kernel packages as shipped with Red Hat Enterprise Linux 6, 7, MRG-2 and realtime kernels.
This issue does not affect kernels that ship with
Debian
CVE-2016-8650: linux - The mpi_powm function in lib/mpi/mpi-pow.c in the Linux kernel through 4.8.11 do...
vendor_debian·2016·CVSS 5.5
CVE-2016-8650 [MEDIUM] CVE-2016-8650: linux - The mpi_powm function in lib/mpi/mpi-pow.c in the Linux kernel through 4.8.11 do...
The mpi_powm function in lib/mpi/mpi-pow.c in the Linux kernel through 4.8.11 does not ensure that memory is allocated for limb data, which allows local users to cause a denial of service (stack memory corruption and panic) via an add_key system call for an RSA key with a zero exponent.
Scope: local
bookworm: resolved (fixed in 4.8.11-1)
bullseye: resolved (fixed in 4.8.11-1)
forky: resolved (fixed in 4.8.11-1)
sid: resolved (fixed in 4.8.11-1)
trixie: resolved (fixed in 4.8.11-1)
GHSA
GHSA-pjpg-8qgr-gpc5: The mpi_powm function in lib/mpi/mpi-pow
ghsa_unreviewed·2022-05-14
CVE-2016-8650 [MEDIUM] CWE-20 GHSA-pjpg-8qgr-gpc5: The mpi_powm function in lib/mpi/mpi-pow
The mpi_powm function in lib/mpi/mpi-pow.c in the Linux kernel through 4.8.11 does not ensure that memory is allocated for limb data, which allows local users to cause a denial of service (stack memory corruption and panic) via an add_key system call for an RSA key with a zero exponent.
OSV
linux vulnerabilities
osv·2017-09-18·CVSS 7.8
CVE-2017-1000251 [HIGH] linux vulnerabilities
linux vulnerabilities
It was discovered that a buffer overflow existed in the Bluetooth stack of
the Linux kernel when handling L2CAP configuration responses. A physically
proximate attacker could use this to cause a denial of service (system
crash). (CVE-2017-1000251)
It was discovered that the asynchronous I/O (aio) subsystem of the Linux
kernel did not properly set permissions on aio memory mappings in some
situations. An attacker could use this to more easily exploit other
vulnerabilities. (CVE-2016-10044)
Baozeng Ding and Andrey Konovalov discovered a race condition in the L2TPv3
IP Encapsulation implementation in the Linux kernel. A local attacker could
use this to cause a denial of service (system crash) or possibly execute
arbitrary code. (CVE-2016-10200)
Andreas Gruenbacher an
OSV
CVE-2016-8650: The mpi_powm function in lib/mpi/mpi-pow
osv·2016-11-28·CVSS 5.5
CVE-2016-8650 [MEDIUM] CVE-2016-8650: The mpi_powm function in lib/mpi/mpi-pow
The mpi_powm function in lib/mpi/mpi-pow.c in the Linux kernel through 4.8.11 does not ensure that memory is allocated for limb data, which allows local users to cause a denial of service (stack memory corruption and panic) via an add_key system call for an RSA key with a zero exponent.
Kernel
Merge branch 'for-linus' of git://git.kernel.org/pub/scm/linux/kernel/git/jmorris/linux-security
kernel_security·2016-11-25·CVSS 5.5
CVE-2016-8650 [MEDIUM] Merge branch 'for-linus' of git://git.kernel.org/pub/scm/linux/kernel/git/jmorris/linux-security
Merge branch 'for-linus' of git://git.kernel.org/pub/scm/linux/kernel/git/jmorris/linux-security
Pull keys fixes from James Morris:
"From David:
- Fix mpi_powm()'s handling of a number with a zero exponent
[CVE-2016-8650].
Integrate my and Andrey's patches for mpi_powm() and use
mpi_resize() instead of RESIZE_IF_NEEDED() - the latter adds a
duplicate check into the execution path of a trivial case we
don't normally expect to be taken.
- Fix double free in X.509 error handling"
* 'for-linus' of git://git.kernel.org/pub/scm/linux/kernel/git/jmorris/linux-security:
mpi: Fix NULL ptr dereference in mpi_powm() [ver #3]
X.509: Fix double free in x509_cert_parse() [ver #3]
Kernel
mpi: Fix NULL ptr dereference in mpi_powm() [ver #3]
kernel_security·2016-11-24·CVSS 5.5
CVE-2016-8650 [MEDIUM] mpi: Fix NULL ptr dereference in mpi_powm() [ver #3]
mpi: Fix NULL ptr dereference in mpi_powm() [ver #3]
This fixes CVE-2016-8650.
If mpi_powm() is given a zero exponent, it wants to immediately return
either 1 or 0, depending on the modulus. However, if the result was
initalised with zero limb space, no limbs space is allocated and a
NULL-pointer exception ensues.
Fix this by allocating a minimal amount of limb space for the result when
the 0-exponent case when the result is 1 and not touching the limb space
when the result is 0.
This affects the use of RSA keys and X.509 certificates that carry them.
BUG: unable to handle kernel NULL pointer dereference at (null)
IP: [] mpi_powm+0x32/0x7e6
PGD 0
Oops: 0002 [#1] SMP
Modules linked in:
CPU: 3 PID: 3014 Comm: keyctl Not tainted 4.9.0-rc6-fscache+ #278
Hardware name: ASUS All Series/H97-
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-8650 kernel: Null pointer dereference via keyctl [fedora-all]
bugzilla·2016-11-24·CVSS 5.5
CVE-2016-8650 [MEDIUM] CVE-2016-8650 kernel: Null pointer dereference via keyctl [fedora-all]
CVE-2016-8650 kernel: Null pointer dereference via keyctl [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedora.
Bugzilla
CVE-2016-8650 kernel: Null pointer dereference via keyctl
bugzilla·2016-11-15·CVSS 5.5
CVE-2016-8650 [MEDIUM] CVE-2016-8650 kernel: Null pointer dereference via keyctl
CVE-2016-8650 kernel: Null pointer dereference via keyctl
A flaw was found in the Linux kernel key management subsystem in which a local attacker could crash the kernel or corrupt the stack and additional memory (denial of service) by supplying a specially crafted RSA key. This flaw panics the machine during the verification of the RSA key and is key-payload independant.
This vulnerably can be triggered by any unprivileged user with a local shell account.
References:
http://seclists.org/fulldisclosure/2016/Nov/76
Product bug:
https://bugzilla.redhat.com/show_bug.cgi?id=1343162
Discussion:
Statement:
This issue affects the Linux kernel packages as shipped with Red Hat Enterprise Linux 6, 7, MRG-2 and realtime kernels.
This issue does not affect kernels that ship with Red Hat Enter
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=f5527fffff3f002b0a6b376163613b82f69de073http://seclists.org/fulldisclosure/2016/Nov/76http://www.openwall.com/lists/oss-security/2016/11/24/8http://www.securityfocus.com/bid/94532http://www.securitytracker.com/id/1037968https://access.redhat.com/errata/RHSA-2017:0931https://access.redhat.com/errata/RHSA-2017:0932https://access.redhat.com/errata/RHSA-2017:0933https://access.redhat.com/errata/RHSA-2018:1854https://bugzilla.redhat.com/show_bug.cgi?id=1395187https://github.com/torvalds/linux/commit/f5527fffff3f002b0a6b376163613b82f69de073https://source.android.com/security/bulletin/2017-03-01.htmlhttp://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=f5527fffff3f002b0a6b376163613b82f69de073http://seclists.org/fulldisclosure/2016/Nov/76http://www.openwall.com/lists/oss-security/2016/11/24/8http://www.securityfocus.com/bid/94532http://www.securitytracker.com/id/1037968https://access.redhat.com/errata/RHSA-2017:0931https://access.redhat.com/errata/RHSA-2017:0932https://access.redhat.com/errata/RHSA-2017:0933https://access.redhat.com/errata/RHSA-2018:1854https://bugzilla.redhat.com/show_bug.cgi?id=1395187https://github.com/torvalds/linux/commit/f5527fffff3f002b0a6b376163613b82f69de073https://source.android.com/security/bulletin/2017-03-01.html
2016-11-28
Published