CVE-2016-9313
published 2016-11-28CVE-2016-9313: security/keys/big_key.c in the Linux kernel before 4.8.7 mishandles unsuccessful crypto registration in conjunction with successful key-type registration…
PriorityP433high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
2.11%
80.0th percentile
security/keys/big_key.c in the Linux kernel before 4.8.7 mishandles unsuccessful crypto registration in conjunction with successful key-type registration, which allows local users to cause a denial of service (NULL pointer dereference and panic) or possibly have unspecified other impact via a crafted application that uses the big_key data type.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 4.8.7-1 (bookworm) | linux 4.8.7-1 (bookworm) |
| linux | linux_kernel | >= 0 < 4.8.7-1 | 4.8.7-1 |
| linux | linux_kernel | >= 0 < 4.8.7-1 | 4.8.7-1 |
| linux | linux_kernel | >= 0 < 4.8.7-1 | 4.8.7-1 |
| linux | linux_kernel | >= 0 < 4.8.7-1 | 4.8.7-1 |
| linux | linux_kernel | >= 4.7 < 4.8.7 | 4.8.7 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
vendor_ubuntu4.7MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2016-12-20·CVSS 4.7
CVE-2016-9313 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
CAI Qian discovered that shared bind mounts in a mount namespace
exponentially added entries without restriction to the Linux kernel's mount
table. A local attacker could use this to cause a denial of service (system
crash). (CVE-2016-6213)
It was discovered that the KVM implementation for x86/x86_64 in the Linux
kernel could dereference a null pointer. An attacker in a guest virtual
machine could use this to cause a denial of service (system crash) in the
KVM host. (CVE-2016-8630)
Eyal Itkin discovered that the IP over IEEE 1394 (FireWire) implementation
in the Linux kernel contained a buffer overflow when handling fragmented
packets. A remote attacker could use this to possibly execute arbi
Ubuntu
Linux kernel (Raspberry Pi 2) vulnerabilities
vendor_ubuntu·2016-12-20·CVSS 4.7
CVE-2016-6213 [MEDIUM] Linux kernel (Raspberry Pi 2) vulnerabilities
Title: Linux kernel (Raspberry Pi 2) vulnerabilities
Summary: Several security issues were fixed in the kernel.
CAI Qian discovered that shared bind mounts in a mount namespace
exponentially added entries without restriction to the Linux kernel's mount
table. A local attacker could use this to cause a denial of service (system
crash). (CVE-2016-6213)
Andreas Gruenbacher and Jan Kara discovered that the filesystem
implementation in the Linux kernel did not clear the setgid bit during a
setxattr call. A local attacker could use this to possibly elevate group
privileges. (CVE-2016-7097)
Marco Grassi discovered that the driver for Areca RAID Controllers in the
Linux kernel did not properly validate control messages. A local attacker
could use this to cause a denial of service (system crash
Red Hat
kernel: security/keys/big_key.c mishandles unsuccessful crypto registration
vendor_redhat·2016-07-22·CVSS 7.8
CVE-2016-9313 [HIGH] CWE-476 kernel: security/keys/big_key.c mishandles unsuccessful crypto registration
kernel: security/keys/big_key.c mishandles unsuccessful crypto registration
security/keys/big_key.c in the Linux kernel before 4.8.7 mishandles unsuccessful crypto registration in conjunction with successful key-type registration, which allows local users to cause a denial of service (NULL pointer dereference and panic) or possibly have unspecified other impact via a crafted application that uses the big_key data type.
The implementation of big key management in security/keys/big_key.c in the Linux kernel before 4.8.7 mishandles unsuccessful crypto registration in conjunction with successful key-type registration, which allows local users to cause a denial of service (NULL pointer dereference and panic) or possibly have unspecified other impact via a crafted application that uses the big
Debian
CVE-2016-9313: linux - security/keys/big_key.c in the Linux kernel before 4.8.7 mishandles unsuccessful...
vendor_debian·2016·CVSS 7.8
CVE-2016-9313 [HIGH] CVE-2016-9313: linux - security/keys/big_key.c in the Linux kernel before 4.8.7 mishandles unsuccessful...
security/keys/big_key.c in the Linux kernel before 4.8.7 mishandles unsuccessful crypto registration in conjunction with successful key-type registration, which allows local users to cause a denial of service (NULL pointer dereference and panic) or possibly have unspecified other impact via a crafted application that uses the big_key data type.
Scope: local
bookworm: resolved (fixed in 4.8.7-1)
bullseye: resolved (fixed in 4.8.7-1)
forky: resolved (fixed in 4.8.7-1)
sid: resolved (fixed in 4.8.7-1)
trixie: resolved (fixed in 4.8.7-1)
GHSA
GHSA-87j2-w75f-pvcg: security/keys/big_key
ghsa_unreviewed·2022-05-17
CVE-2016-9313 [HIGH] CWE-476 GHSA-87j2-w75f-pvcg: security/keys/big_key
security/keys/big_key.c in the Linux kernel before 4.8.7 mishandles unsuccessful crypto registration in conjunction with successful key-type registration, which allows local users to cause a denial of service (NULL pointer dereference and panic) or possibly have unspecified other impact via a crafted application that uses the big_key data type.
OSV
CVE-2016-9313: security/keys/big_key
osv·2016-11-28·CVSS 7.8
CVE-2016-9313 [HIGH] CVE-2016-9313: security/keys/big_key
security/keys/big_key.c in the Linux kernel before 4.8.7 mishandles unsuccessful crypto registration in conjunction with successful key-type registration, which allows local users to cause a denial of service (NULL pointer dereference and panic) or possibly have unspecified other impact via a crafted application that uses the big_key data type.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-9313 kernel: security/keys/big_key.c mishandles unsuccessful crypto registration
bugzilla·2016-11-29·CVSS 7.8
CVE-2016-9313 [HIGH] CVE-2016-9313 kernel: security/keys/big_key.c mishandles unsuccessful crypto registration
CVE-2016-9313 kernel: security/keys/big_key.c mishandles unsuccessful crypto registration
The linux kernels implementation of "big key" management in security/keys/big_key.c in the Linux kernel before 4.8.7 mishandles unsuccessful
crypto registration in conjunction with successful key-type registration, which
allows local users to cause a denial of service (NULL pointer dereference and
panic) or possibly have unspecified other impact via a crafted application that
uses the big_key data type.
As per the patch notes the Red Hat Enterprise Linux code contains neither big_key_rng and big_key_blkcipher, which can be set to null. The Red Hat Enterprise Linux source contains no blkcipher code to be affected.
References:
http://seclists.org/oss-sec/2016/q3/130
Upstream patch:
https://github.
Bugzilla
CVE-2016-9313 kernel: security/keys/big_key.c mishandles unsuccessful crypto registration [fedora-all]
bugzilla·2016-11-29·CVSS 7.8
CVE-2016-9313 [HIGH] CVE-2016-9313 kernel: security/keys/big_key.c mishandles unsuccessful crypto registration [fedora-all]
CVE-2016-9313 kernel: security/keys/big_key.c mishandles unsuccessful crypto registration [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multip
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=7df3e59c3d1df4f87fe874c7956ef7a3d2f4d5fbhttp://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.8.7http://www.openwall.com/lists/oss-security/2016/07/22/1http://www.securityfocus.com/bid/94546https://github.com/torvalds/linux/commit/7df3e59c3d1df4f87fe874c7956ef7a3d2f4d5fbhttp://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=7df3e59c3d1df4f87fe874c7956ef7a3d2f4d5fbhttp://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.8.7http://www.openwall.com/lists/oss-security/2016/07/22/1http://www.securityfocus.com/bid/94546https://github.com/torvalds/linux/commit/7df3e59c3d1df4f87fe874c7956ef7a3d2f4d5fb
2016-11-28
Published