cbcvebase.
CVE-2016-9604
published 2018-07-11

CVE-2016-9604: It was discovered in the Linux kernel before 4.11-rc8 that root can gain direct access to an internal keyring, such as '.dns_resolver' in RHEL-7 or…

PriorityP421medium4.4CVSS 3.0
AVLACLPRHUINSUCNIHAN
EPSS
0.26%
17.7th percentile
It was discovered in the Linux kernel before 4.11-rc8 that root can gain direct access to an internal keyring, such as '.dns_resolver' in RHEL-7 or '.builtin_trusted_keys' upstream, by joining it as its session keyring. This allows root to bypass module signature verification by adding a new public key of its own devising to the keyring.

Affected

10 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 4.9.25-1 (bookworm)linux 4.9.25-1 (bookworm)
kernelsecurity
linuxlinux_kernel<= 4.11
linuxlinux_kernel
linuxlinux_kernel>= 0 < 4.9.25-14.9.25-1
linuxlinux_kernel>= 0 < 4.9.25-14.9.25-1
linuxlinux_kernel>= 0 < 4.9.25-14.9.25-1
linuxlinux_kernel>= 0 < 4.9.25-14.9.25-1
linuxlinux_kernel>= 0 < 3.13.0-132.1813.13.0-132.181
linuxlinux_kernel>= 0 < 4.4.0-79.1004.4.0-79.100

CVSS provenance

nvdv3.04.4MEDIUMCVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:N/I:P/A:N
osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_debian4.4MEDIUM
vendor_redhat4.4MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.