CVE-2017-2647
published 2017-03-31CVE-2017-2647: The KEYS subsystem in the Linux kernel before 3.18 allows local users to gain privileges or cause a denial of service (NULL pointer dereference and system…
PriorityP433high7.8CVSS 3.0
AVLACLPRLUINSUCHIHAH
EPSS
0.41%
33.6th percentile
The KEYS subsystem in the Linux kernel before 3.18 allows local users to gain privileges or cause a denial of service (NULL pointer dereference and system crash) via vectors involving a NULL value for a certain match field, related to the keyring_search_iterator function in keyring.c.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 4.0.2-1 (bookworm) | linux 4.0.2-1 (bookworm) |
| linux | linux_kernel | <= 3.17.8 | — |
| linux | linux_kernel | >= 0 < 4.0.2-1 | 4.0.2-1 |
| linux | linux_kernel | >= 0 < 4.0.2-1 | 4.0.2-1 |
| linux | linux_kernel | >= 0 < 4.0.2-1 | 4.0.2-1 |
| linux | linux_kernel | >= 0 < 4.0.2-1 | 4.0.2-1 |
| linux | linux_kernel | >= 0 < 3.13.0-164.214 | 3.13.0-164.214 |
CVSS provenance
nvdv3.07.8HIGHCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
vendor_ubuntu7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-6723-4j9m-72qg: The KEYS subsystem in the Linux kernel before 3
ghsa_unreviewed·2022-05-14
CVE-2017-2647 [HIGH] CWE-476 GHSA-6723-4j9m-72qg: The KEYS subsystem in the Linux kernel before 3
The KEYS subsystem in the Linux kernel before 3.18 allows local users to gain privileges or cause a denial of service (NULL pointer dereference and system crash) via vectors involving a NULL value for a certain match field, related to the keyring_search_iterator function in keyring.c.
OSV
linux vulnerabilities
osv·2018-12-20·CVSS 7.8
CVE-2017-2647 [HIGH] linux vulnerabilities
linux vulnerabilities
It was discovered that a NULL pointer dereference existed in the keyring
subsystem of the Linux kernel. A local attacker could use this to cause a
denial of service (system crash). (CVE-2017-2647)
It was discovered that a race condition existed in the raw MIDI driver for
the Linux kernel, leading to a double free vulnerability. A local attacker
could use this to cause a denial of service (system crash) or possibly
execute arbitrary code. (CVE-2018-10902)
It was discovered that an integer overrun vulnerability existed in the
POSIX timers implementation in the Linux kernel. A local attacker could use
this to cause a denial of service. (CVE-2018-12896)
Noam Rathaus discovered that a use-after-free vulnerability existed in the
Infiniband implementation in the Linux ke
OSV
CVE-2017-2647: The KEYS subsystem in the Linux kernel before 3
osv·2017-03-31·CVSS 7.8
CVE-2017-2647 [HIGH] CVE-2017-2647: The KEYS subsystem in the Linux kernel before 3
The KEYS subsystem in the Linux kernel before 3.18 allows local users to gain privileges or cause a denial of service (NULL pointer dereference and system crash) via vectors involving a NULL value for a certain match field, related to the keyring_search_iterator function in keyring.c.
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2018-12-20·CVSS 7.8
CVE-2017-2647 [HIGH] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
It was discovered that a NULL pointer dereference existed in the keyring
subsystem of the Linux kernel. A local attacker could use this to cause a
denial of service (system crash). (CVE-2017-2647)
It was discovered that a race condition existed in the raw MIDI driver for
the Linux kernel, leading to a double free vulnerability. A local attacker
could use this to cause a denial of service (system crash) or possibly
execute arbitrary code. (CVE-2018-10902)
It was discovered that an integer overrun vulnerability existed in the
POSIX timers implementation in the Linux kernel. A local attacker could use
this to cause a denial of service. (CVE-2018-12896)
Noam Rathaus discovered that a use-a
Ubuntu
Linux kernel (Trusty HWE) vulnerabilities
vendor_ubuntu·2018-12-20·CVSS 7.8
CVE-2017-2647 [HIGH] Linux kernel (Trusty HWE) vulnerabilities
Title: Linux kernel (Trusty HWE) vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
USN-3849-1 fixed vulnerabilities in the Linux kernel for Ubuntu 14.04
LTS. This update provides the corresponding updates for the Linux
Hardware Enablement (HWE) kernel from Ubuntu 14.04 LTS for Ubuntu
12.04 ESM.
It was discovered that a NULL pointer dereference existed in the keyring
subsystem of the Linux kernel. A local attacker could use this to cause a
denial of service (system crash). (CVE-2017-2647)
It was discovered that a race condition existed in the raw MIDI driver for
the Linux kernel, leading to a double free vulnerability. A local attacker
could use this to cause a denial of service (system crash) or possibly
execute arbitrary code. (CVE-2018-10902)
It was di
Red Hat
kernel: Null pointer dereference in search_keyring
vendor_redhat·2017-03-21·CVSS 7.8
CVE-2017-2647 [HIGH] CWE-476 kernel: Null pointer dereference in search_keyring
kernel: Null pointer dereference in search_keyring
The KEYS subsystem in the Linux kernel before 3.18 allows local users to gain privileges or cause a denial of service (NULL pointer dereference and system crash) via vectors involving a NULL value for a certain match field, related to the keyring_search_iterator function in keyring.c.
A flaw was found that can be triggered in keyring_search_iterator in keyring.c if type->match is NULL. A local user could use this flaw to crash the system or, potentially, escalate their privileges.
Statement: This issue does not affect the Linux kernel packages as shipped with Red Hat Enterprise Linux 5 as the code which can trigger the flaw is not present in the products listed.
This issue affects the Linux kernel packages as shipped with Red Hat Enterp
Debian
CVE-2017-2647: linux - The KEYS subsystem in the Linux kernel before 3.18 allows local users to gain pr...
vendor_debian·2017·CVSS 7.8
CVE-2017-2647 [HIGH] CVE-2017-2647: linux - The KEYS subsystem in the Linux kernel before 3.18 allows local users to gain pr...
The KEYS subsystem in the Linux kernel before 3.18 allows local users to gain privileges or cause a denial of service (NULL pointer dereference and system crash) via vectors involving a NULL value for a certain match field, related to the keyring_search_iterator function in keyring.c.
Scope: local
bookworm: resolved (fixed in 4.0.2-1)
bullseye: resolved (fixed in 4.0.2-1)
forky: resolved (fixed in 4.0.2-1)
sid: resolved (fixed in 4.0.2-1)
trixie: resolved (fixed in 4.0.2-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2017-7600 libtiff: Unsigned char out of range in tif_dirwrite.c
bugzilla·2017-04-11·CVSS 7.8
CVE-2017-7600 [HIGH] CVE-2017-7600 libtiff: Unsigned char out of range in tif_dirwrite.c
CVE-2017-7600 libtiff: Unsigned char out of range in tif_dirwrite.c
LibTIFF has an "outside the range of representable values of type unsigned char" undefined behavior issue, which might allow attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted image.
Upstream bug:
http://bugzilla.maptools.org/show_bug.cgi?id=2647
Upstream patch:
https://github.com/vadz/libtiff/commit/3144e57770c1e4d26520d8abee750f8ac8b75490
Discussion:
Created mingw-libtiff tracking bugs for this issue:
Affects: fedora-all [bug 1438465]
---
Created mingw-libtiff tracking bugs for this issue:
Affects: epel-7 [bug 1438466]
---
Created libtiff tracking bugs for this issue:
Affects: fedora-all [bug 1441273]
Bugzilla
CVE-2017-2647 kernel: Null pointer dereference in search_keyring
bugzilla·2017-03-02·CVSS 7.8
CVE-2017-2647 [HIGH] CVE-2017-2647 kernel: Null pointer dereference in search_keyring
CVE-2017-2647 kernel: Null pointer dereference in search_keyring
A null pointer dereference vulnerability that can be triggered in keyring_search_iterator in keyring.c if type->match is NULL by unprivileged local user was found. It is possible that an attacker could crash the system or escalate privileges using this vulnerability.
Fixed in upstream:
https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=c06cfb08b88d
Discussion:
Acknowledgments:
Name: Igor Redko (Virtuozzo), Andrey Ryabinin (Virtuozzo)
---
Created attachment 1259126
Proposed patch
---
Statement:
This issue does not affect the Linux kernel packages as shipped with Red Hat Enterprise Linux 5 as the code which can trigger the flaw is not present in the products listed.
This issue affects the Lin
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=c06cfb08b88dfbe13be44a69ae2fdc3a7c902d81http://www.securityfocus.com/bid/97258https://access.redhat.com/errata/RHSA-2017:1842https://access.redhat.com/errata/RHSA-2017:2077https://access.redhat.com/errata/RHSA-2017:2437https://access.redhat.com/errata/RHSA-2017:2444https://bugzilla.redhat.com/show_bug.cgi?id=1428353https://github.com/torvalds/linux/commit/c06cfb08b88dfbe13be44a69ae2fdc3a7c902d81https://usn.ubuntu.com/3849-1/https://usn.ubuntu.com/3849-2/http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=c06cfb08b88dfbe13be44a69ae2fdc3a7c902d81http://www.securityfocus.com/bid/97258https://access.redhat.com/errata/RHSA-2017:1842https://access.redhat.com/errata/RHSA-2017:2077https://access.redhat.com/errata/RHSA-2017:2437https://access.redhat.com/errata/RHSA-2017:2444https://bugzilla.redhat.com/show_bug.cgi?id=1428353https://github.com/torvalds/linux/commit/c06cfb08b88dfbe13be44a69ae2fdc3a7c902d81https://usn.ubuntu.com/3849-1/https://usn.ubuntu.com/3849-2/
2017-03-31
Published