CVE-2017-6951
published 2017-03-16CVE-2017-6951: The keyring_search_aux function in security/keys/keyring.c in the Linux kernel through 3.14.79 allows local users to cause a denial of service (NULL pointer…
PriorityP417medium5.5CVSS 3.0
AVLACLPRLUINSUCNINAH
EPSS
0.39%
31.4th percentile
The keyring_search_aux function in security/keys/keyring.c in the Linux kernel through 3.14.79 allows local users to cause a denial of service (NULL pointer dereference and OOPS) via a request_key system call for the "dead" type.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 4.0.2-1 (bookworm) | linux 4.0.2-1 (bookworm) |
| linux | linux_kernel | <= 3.14.79 | — |
| linux | linux_kernel | >= 0 < 4.0.2-1 | 4.0.2-1 |
| linux | linux_kernel | >= 0 < 4.0.2-1 | 4.0.2-1 |
| linux | linux_kernel | >= 0 < 4.0.2-1 | 4.0.2-1 |
| linux | linux_kernel | >= 0 < 4.0.2-1 | 4.0.2-1 |
| linux | linux_kernel | >= 0 < 3.13.0-132.181 | 3.13.0-132.181 |
CVSS provenance
nvdv3.05.5MEDIUMCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv2.04.9MEDIUMAV:L/AC:L/Au:N/C:N/I:N/A:C
osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2017-09-18·CVSS 7.8
CVE-2016-10044 [HIGH] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
It was discovered that a buffer overflow existed in the Bluetooth stack of
the Linux kernel when handling L2CAP configuration responses. A physically
proximate attacker could use this to cause a denial of service (system
crash). (CVE-2017-1000251)
It was discovered that the asynchronous I/O (aio) subsystem of the Linux
kernel did not properly set permissions on aio memory mappings in some
situations. An attacker could use this to more easily exploit other
vulnerabilities. (CVE-2016-10044)
Baozeng Ding and Andrey Konovalov discovered a race condition in the L2TPv3
IP Encapsulation implementation in the Linux kernel. A local attacker could
use this to cause a denial of service (system cra
Ubuntu
Linux kernel (Trusty HWE) vulnerabilities
vendor_ubuntu·2017-09-18·CVSS 7.8
CVE-2016-10044 [HIGH] Linux kernel (Trusty HWE) vulnerabilities
Title: Linux kernel (Trusty HWE) vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
USN-3422-1 fixed vulnerabilities in the Linux kernel for Ubuntu 14.04
LTS. This update provides the corresponding updates for the Linux
Hardware Enablement (HWE) kernel from Ubuntu 14.04 LTS for Ubuntu
12.04 LTS.
It was discovered that a buffer overflow existed in the Bluetooth stack of
the Linux kernel when handling L2CAP configuration responses. A physically
proximate attacker could use this to cause a denial of service (system
crash). (CVE-2017-1000251)
It was discovered that the asynchronous I/O (aio) subsystem of the Linux
kernel did not properly set permissions on aio memory mappings in some
situations. An attacker could use this to more easily exploit other
vulnerabi
Red Hat
kernel: NULL pointer dereference in keyring_search_aux function
vendor_redhat·2017-03-03·CVSS 5.5
CVE-2017-6951 [MEDIUM] CWE-476 kernel: NULL pointer dereference in keyring_search_aux function
kernel: NULL pointer dereference in keyring_search_aux function
The keyring_search_aux function in security/keys/keyring.c in the Linux kernel through 3.14.79 allows local users to cause a denial of service (NULL pointer dereference and OOPS) via a request_key system call for the "dead" type.
The keyring_search_aux function in security/keys/keyring.c in the Linux kernel allows local users to cause a denial of service via a request_key system call for the "dead" key type.
Statement: This issue does not affect the Linux kernel packages as shipped with Red Hat Enterprise Linux 5.
This issue affects the Linux kernel packages as shipped with Red Hat Enterprise Linux 6, 7 and MRG-2.
Future Linux kernel updates for the respective releases may address this issue.
Package: kernel (Red Hat Enter
Debian
CVE-2017-6951: linux - The keyring_search_aux function in security/keys/keyring.c in the Linux kernel t...
vendor_debian·2017·CVSS 5.5
CVE-2017-6951 [MEDIUM] CVE-2017-6951: linux - The keyring_search_aux function in security/keys/keyring.c in the Linux kernel t...
The keyring_search_aux function in security/keys/keyring.c in the Linux kernel through 3.14.79 allows local users to cause a denial of service (NULL pointer dereference and OOPS) via a request_key system call for the "dead" type.
Scope: local
bookworm: resolved (fixed in 4.0.2-1)
bullseye: resolved (fixed in 4.0.2-1)
forky: resolved (fixed in 4.0.2-1)
sid: resolved (fixed in 4.0.2-1)
trixie: resolved (fixed in 4.0.2-1)
GHSA
GHSA-w643-vjwg-3cfx: The keyring_search_aux function in security/keys/keyring
ghsa_unreviewed·2022-05-14
CVE-2017-6951 [MEDIUM] CWE-476 GHSA-w643-vjwg-3cfx: The keyring_search_aux function in security/keys/keyring
The keyring_search_aux function in security/keys/keyring.c in the Linux kernel through 3.14.79 allows local users to cause a denial of service (NULL pointer dereference and OOPS) via a request_key system call for the "dead" type.
OSV
linux vulnerabilities
osv·2017-09-18·CVSS 7.8
CVE-2017-1000251 [HIGH] linux vulnerabilities
linux vulnerabilities
It was discovered that a buffer overflow existed in the Bluetooth stack of
the Linux kernel when handling L2CAP configuration responses. A physically
proximate attacker could use this to cause a denial of service (system
crash). (CVE-2017-1000251)
It was discovered that the asynchronous I/O (aio) subsystem of the Linux
kernel did not properly set permissions on aio memory mappings in some
situations. An attacker could use this to more easily exploit other
vulnerabilities. (CVE-2016-10044)
Baozeng Ding and Andrey Konovalov discovered a race condition in the L2TPv3
IP Encapsulation implementation in the Linux kernel. A local attacker could
use this to cause a denial of service (system crash) or possibly execute
arbitrary code. (CVE-2016-10200)
Andreas Gruenbacher an
Kernel
Merge tag 'keys-fixes-20170419' of git://git.kernel.org/pub/scm/linux/kernel/git/dhowells/linux-fs
kernel_security·2017-04-20·CVSS 4.4
CVE-2016-9604 [MEDIUM] Merge tag 'keys-fixes-20170419' of git://git.kernel.org/pub/scm/linux/kernel/git/dhowells/linux-fs
Merge tag 'keys-fixes-20170419' of git://git.kernel.org/pub/scm/linux/kernel/git/dhowells/linux-fs
Pull keyrings fixes from David Howells:
(1) Disallow keyrings whose name begins with a '.' to be joined
[CVE-2016-9604].
(2) Change the name of the dead type to ".dead" to prevent user access
[CVE-2017-6951].
(3) Fix keyctl_set_reqkey_keyring() to not leak thread keyrings
[CVE-2017-7472]
* tag 'keys-fixes-20170419' of git://git.kernel.org/pub/scm/linux/kernel/git/dhowells/linux-fs:
KEYS: fix keyctl_set_reqkey_keyring() to not leak thread keyrings
KEYS: Change the name of the dead type to ".dead" to prevent user access
KEYS: Disallow keyrings beginning with '.' to be joined as session keyrings
Kernel
KEYS: Change the name of the dead type to ".dead" to prevent user access
kernel_security·2017-04-18·CVSS 5.5
CVE-2017-6951 [MEDIUM] KEYS: Change the name of the dead type to ".dead" to prevent user access
KEYS: Change the name of the dead type to ".dead" to prevent user access
This fixes CVE-2017-6951.
Userspace should not be able to do things with the "dead" key type as it
doesn't have some of the helper functions set upon it that the kernel
needs. Attempting to use it may cause the kernel to crash.
Fix this by changing the name of the type to ".dead" so that it's rejected
up front on userspace syscalls by key_get_type_from_user().
Though this doesn't seem to affect recent kernels, it does affect older
ones, certainly those prior to:
commit c06cfb08b88dfbe13be44a69ae2fdc3a7c902d81
Author: David Howells
Date: Tue Sep 16 17:36:06 2014 +0100
KEYS: Remove key_type::match in favour of overriding default by match_preparse
which went in before 3.18-rc1.
Signed-off-by: David Howells
cc: sta
OSV
CVE-2017-6951: The keyring_search_aux function in security/keys/keyring
osv·2017-03-16·CVSS 5.5
CVE-2017-6951 [MEDIUM] CVE-2017-6951: The keyring_search_aux function in security/keys/keyring
The keyring_search_aux function in security/keys/keyring.c in the Linux kernel through 3.14.79 allows local users to cause a denial of service (NULL pointer dereference and OOPS) via a request_key system call for the "dead" type.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2017-6951 kernel: NULL pointer dereference in keyring_search_aux function [fedora-all]
bugzilla·2017-07-17·CVSS 5.5
CVE-2017-6951 [MEDIUM] CVE-2017-6951 kernel: NULL pointer dereference in keyring_search_aux function [fedora-all]
CVE-2017-6951 kernel: NULL pointer dereference in keyring_search_aux function [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple suppo
Bugzilla
CVE-2017-6951 kernel: NULL pointer dereference in keyring_search_aux function
bugzilla·2017-03-17·CVSS 5.5
CVE-2017-6951 [MEDIUM] CVE-2017-6951 kernel: NULL pointer dereference in keyring_search_aux function
CVE-2017-6951 kernel: NULL pointer dereference in keyring_search_aux function
The keyring_search_aux function in security/keys/keyring.c in the Linux kernel allows local users to cause a denial of service (NULL pointer dereference and OOPS) via a request_key system call for the "dead" type.
References:
http://www.spinics.net/lists/keyrings/msg01846.html
Upstream patch:
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=c06cfb08b88d
Discussion:
Created attachment 1268882
Fix to rename the 'dead' type to '.dead' to make syscalls reject the name
---
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 1471601]
---
Statement:
This issue does not affect the Linux kernel packages as shipped with Red Hat Enterprise Linux 5.
This issue affe
Bugzilla
CVE-2017-2647 kernel: Null pointer dereference in search_keyring
bugzilla·2017-03-02·CVSS 7.8
CVE-2017-2647 [HIGH] CVE-2017-2647 kernel: Null pointer dereference in search_keyring
CVE-2017-2647 kernel: Null pointer dereference in search_keyring
A null pointer dereference vulnerability that can be triggered in keyring_search_iterator in keyring.c if type->match is NULL by unprivileged local user was found. It is possible that an attacker could crash the system or escalate privileges using this vulnerability.
Fixed in upstream:
https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=c06cfb08b88d
Discussion:
Acknowledgments:
Name: Igor Redko (Virtuozzo), Andrey Ryabinin (Virtuozzo)
---
Created attachment 1259126
Proposed patch
---
Statement:
This issue does not affect the Linux kernel packages as shipped with Red Hat Enterprise Linux 5 as the code which can trigger the flaw is not present in the products listed.
This issue affects the Lin
http://www.securityfocus.com/bid/96943http://www.spinics.net/lists/keyrings/msg01845.htmlhttp://www.spinics.net/lists/keyrings/msg01846.htmlhttp://www.spinics.net/lists/keyrings/msg01849.htmlhttps://access.redhat.com/errata/RHSA-2017:1842https://access.redhat.com/errata/RHSA-2017:2077https://access.redhat.com/errata/RHSA-2017:2669http://www.securityfocus.com/bid/96943http://www.spinics.net/lists/keyrings/msg01845.htmlhttp://www.spinics.net/lists/keyrings/msg01846.htmlhttp://www.spinics.net/lists/keyrings/msg01849.htmlhttps://access.redhat.com/errata/RHSA-2017:1842https://access.redhat.com/errata/RHSA-2017:2077https://access.redhat.com/errata/RHSA-2017:2669
2017-03-16
Published