[Forgot Password]
Login  Register Subscribe

30389

 
 

423868

 
 

244411

 
 

909

 
 

193363

 
 

277

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2015-7872Date: (C)2015-12-15   (M)2024-03-21


The key_gc_unused_keys function in security/keys/gc.c in the Linux kernel through 4.2.6 allows local users to cause a denial of service (OOPS) via crafted keyctl commands.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 2.1
Exploit Score: 3.9
Impact Score: 2.9
 
CVSS V2 Metrics:
Access Vector: LOCAL
Access Complexity: LOW
Authentication: NONE
Confidentiality: NONE
Integrity: NONE
Availability: PARTIAL
  
Reference:
SECTRACK-1034472
BID-77544
DSA-3396
HPSBGN03565
RHSA-2015:2636
RHSA-2016:0185
RHSA-2016:0212
RHSA-2016:0224
SUSE-SU-2015:2108
SUSE-SU-2015:2194
SUSE-SU-2015:2292
SUSE-SU-2015:2339
SUSE-SU-2015:2350
SUSE-SU-2016:0335
SUSE-SU-2016:0337
SUSE-SU-2016:0354
SUSE-SU-2016:0380
SUSE-SU-2016:0381
SUSE-SU-2016:0383
SUSE-SU-2016:0384
SUSE-SU-2016:0386
SUSE-SU-2016:0387
SUSE-SU-2016:0434
SUSE-SU-2016:2074
USN-2823-1
USN-2824-1
USN-2826-1
USN-2829-1
USN-2829-2
USN-2840-1
USN-2840-2
USN-2843-1
USN-2843-2
USN-2843-3
http://www.openwall.com/lists/oss-security/2015/10/20/6
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=ce1fad2740c648a4340f6f6c391a8a83769d2e8c
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=f05819df10d7b09f6d1eb6f8534a8f68e5a4fe61
http://www.oracle.com/technetwork/topics/security/linuxbulletinjan2016-2867209.html
http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.html
https://bugzilla.redhat.com/show_bug.cgi?id=1272172
https://bugzilla.redhat.com/show_bug.cgi?id=1272371
https://github.com/torvalds/linux/commit/ce1fad2740c648a4340f6f6c391a8a83769d2e8c
https://github.com/torvalds/linux/commit/f05819df10d7b09f6d1eb6f8534a8f68e5a4fe61
https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05068676
https://source.android.com/security/bulletin/2016-12-01.html
openSUSE-SU-2016:1008

CWE    1
CWE-20
OVAL    25
oval:org.secpod.oval:def:702883
oval:org.secpod.oval:def:702880
oval:org.secpod.oval:def:52640
oval:org.secpod.oval:def:1501294
...

© SecPod Technologies