CVE-2017-18270
published 2018-05-18CVE-2017-18270: In the Linux kernel before 4.13.5, a local user could create keyrings for other users via keyctl commands, setting unwanted defaults or causing a denial of…
PriorityP427high7.1CVSS 3.0
AVLACLPRLUINSUCNIHAH
EPSS
0.42%
34.7th percentile
In the Linux kernel before 4.13.5, a local user could create keyrings for other users via keyctl commands, setting unwanted defaults or causing a denial of service.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 4.13.10-1 (bookworm) | linux 4.13.10-1 (bookworm) |
| linux | linux_kernel | < 4.13.5 | 4.13.5 |
| linux | linux_kernel | >= 0 < 4.13.10-1 | 4.13.10-1 |
| linux | linux_kernel | >= 0 < 4.13.10-1 | 4.13.10-1 |
| linux | linux_kernel | >= 0 < 4.13.10-1 | 4.13.10-1 |
| linux | linux_kernel | >= 0 < 4.13.10-1 | 4.13.10-1 |
| linux | linux_kernel | >= 0 < 3.13.0-157.207 | 3.13.0-157.207 |
CVSS provenance
nvdv3.07.1HIGHCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
nvdv2.03.6LOWAV:L/AC:L/Au:N/C:N/I:P/A:P
osv7.1HIGH
vendor_debian7.1HIGH
vendor_redhat7.1HIGH
vendor_ubuntu4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-r6j7-prqg-pp3v: In the Linux kernel before 4
ghsa_unreviewed·2022-05-13
CVE-2017-18270 [HIGH] GHSA-r6j7-prqg-pp3v: In the Linux kernel before 4
In the Linux kernel before 4.13.5, a local user could create keyrings for other users via keyctl commands, setting unwanted defaults or causing a denial of service.
OSV
linux vulnerabilities
osv·2018-08-24·CVSS 4.3
CVE-2016-10208 [MEDIUM] linux vulnerabilities
linux vulnerabilities
Ralf Spenneberg discovered that the ext4 implementation in the Linux kernel
did not properly validate meta block groups. An attacker with physical
access could use this to specially craft an ext4 image that causes a denial
of service (system crash). (CVE-2016-10208)
It was discovered that an information disclosure vulnerability existed in
the ACPI implementation of the Linux kernel. A local attacker could use
this to expose sensitive information (kernel memory addresses).
(CVE-2017-11472)
It was discovered that a buffer overflow existed in the ACPI table parsing
implementation in the Linux kernel. A local attacker could use this to
construct a malicious ACPI table that, when loaded, caused a denial of
service (system crash) or possibly execute arbitrary code.
(CVE-
OSV
CVE-2017-18270: In the Linux kernel before 4
osv·2018-05-18·CVSS 7.1
CVE-2017-18270 [HIGH] CVE-2017-18270: In the Linux kernel before 4
In the Linux kernel before 4.13.5, a local user could create keyrings for other users via keyctl commands, setting unwanted defaults or causing a denial of service.
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2018-08-24·CVSS 4.3
CVE-2016-10208 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
Ralf Spenneberg discovered that the ext4 implementation in the Linux kernel
did not properly validate meta block groups. An attacker with physical
access could use this to specially craft an ext4 image that causes a denial
of service (system crash). (CVE-2016-10208)
It was discovered that an information disclosure vulnerability existed in
the ACPI implementation of the Linux kernel. A local attacker could use
this to expose sensitive information (kernel memory addresses).
(CVE-2017-11472)
It was discovered that a buffer overflow existed in the ACPI table parsing
implementation in the Linux kernel. A local attacker could use this to
construct a malicious ACPI table that, when loaded, cau
Red Hat
kernel: keys: for keyctl prevent creating a different user's keyrings in RHEL-6.10
vendor_redhat·2017-09-18·CVSS 7.1
CVE-2020-14353 [HIGH] kernel: keys: for keyctl prevent creating a different user's keyrings in RHEL-6.10
kernel: keys: for keyctl prevent creating a different user's keyrings in RHEL-6.10
[REJECTED CVE] A keys creation with an incorrect permissions flaw was found in the Linux kernel’s keyctl subsystem. This flaw allows a local user to create user session keyrings for another user. The highest threat from this vulnerability is to integrity.
Statement: This flaw was found to be a duplicate of CVE-2017-18270. Please see https://access.redhat.com/security/cve/CVE-2017-18270 for information about affected products and security errata.
Package: kernel (Red Hat Enterprise Linux 5) - Not affected
Package: kernel (Red Hat Enterprise Linux 6) - Not affected
Package: kernel (Red Hat Enterprise Linux 7) - Not affected
Package: kernel-alt (Red Hat Enterprise Linux 7) - Not affected
Package: kernel-
Red Hat
kernel: improper keyrings creation
vendor_redhat·2017-09-18·CVSS 7.1
CVE-2017-18270 [HIGH] CWE-287 kernel: improper keyrings creation
kernel: improper keyrings creation
In the Linux kernel before 4.13.5, a local user could create keyrings for other users via keyctl commands, setting unwanted defaults or causing a denial of service.
A flaw was found in the Linux kernel in the way a local user could create keyrings for other users via keyctl commands. This may allow an attacker to set unwanted defaults, a denial of service, or possibly leak keyring information between users.
Statement: The impact is Moderate, because the impact is only for userspace programs if using keyctl incorrectly. For root-level processes (usually during boot) keyctl being used securely without possibility of leaking keys between users.
Package: kernel (Red Hat Enterprise Linux 5) - Not affected
Package: kernel (Red Hat Enterprise Linux 6) - Out
Debian
CVE-2017-18270: linux - In the Linux kernel before 4.13.5, a local user could create keyrings for other ...
vendor_debian·2017·CVSS 7.1
CVE-2017-18270 [HIGH] CVE-2017-18270: linux - In the Linux kernel before 4.13.5, a local user could create keyrings for other ...
In the Linux kernel before 4.13.5, a local user could create keyrings for other users via keyctl commands, setting unwanted defaults or causing a denial of service.
Scope: local
bookworm: resolved (fixed in 4.13.10-1)
bullseye: resolved (fixed in 4.13.10-1)
forky: resolved (fixed in 4.13.10-1)
sid: resolved (fixed in 4.13.10-1)
trixie: resolved (fixed in 4.13.10-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2020-14353 kernel: keys: for keyctl prevent creating a different user's keyrings in RHEL-6.10
bugzilla·2020-07-14·CVSS 7.1
CVE-2020-14353 [HIGH] CVE-2020-14353 kernel: keys: for keyctl prevent creating a different user's keyrings in RHEL-6.10
CVE-2020-14353 kernel: keys: for keyctl prevent creating a different user's keyrings in RHEL-6.10
Unprivileged user can create (using keyctl) user session keyrings for another user. This is problematic because these "fake" keyrings won't have the right permissions. In particular, the user who created them first will own them and will have full access to them via the possessor permissions, which can be used to compromise the security of a user's keys.
Upstream patch: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=237bbd29f7a049d310d907f4b2716a7feef9abf3
If being used by root-level processes, then could be used securely without possibility of leaking keys between users
(see http://kernsec.org/pipermail/linux-security-module-archive/2017-September/003318.html
Bugzilla
CVE-2017-18270 kernel: improper keyrings creation
bugzilla·2018-05-21·CVSS 7.1
CVE-2017-18270 [HIGH] CVE-2017-18270 kernel: improper keyrings creation
CVE-2017-18270 kernel: improper keyrings creation
A flaw was found in the Linux kernel before 4.13.5, a local user could create keyrings for other users via keyctl commands. This may allow to set unwanted defaults or cause a denial of service.
References:
https://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.13.5
Upstream patch:
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=237bbd29f7a049d310d907f4b2716a7feef9abf3
https://github.com/torvalds/linux/commit/237bbd29f7a049d310d907f4b2716a7feef9abf3
Discussion:
*** Bug 1856774 has been marked as a duplicate of this bug. ***
---
Acknowledgments:
Name: Eric Biggers (Google)
---
Statement:
The impact is Moderate, because the impact is only for userspace programs if using keyctl incorrectly. For root-level
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=237bbd29f7a049d310d907f4b2716a7feef9abf3http://www.securityfocus.com/bid/104254https://bugzilla.redhat.com/show_bug.cgi?id=1580979https://bugzilla.redhat.com/show_bug.cgi?id=1856774#c11https://bugzilla.redhat.com/show_bug.cgi?id=1856774#c9https://github.com/torvalds/linux/commit/237bbd29f7a049d310d907f4b2716a7feef9abf3https://support.f5.com/csp/article/K37301725https://usn.ubuntu.com/3754-1/https://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.13.5http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=237bbd29f7a049d310d907f4b2716a7feef9abf3http://www.securityfocus.com/bid/104254https://bugzilla.redhat.com/show_bug.cgi?id=1580979https://bugzilla.redhat.com/show_bug.cgi?id=1856774#c11https://bugzilla.redhat.com/show_bug.cgi?id=1856774#c9https://github.com/torvalds/linux/commit/237bbd29f7a049d310d907f4b2716a7feef9abf3https://support.f5.com/csp/article/K37301725https://usn.ubuntu.com/3754-1/https://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.13.5
2018-05-18
Published