Back to search
CVE-2006-1522
Published: Apr 10, 2006
Modified: Aug 7, 2024
PUBLISHED
Description
The sys_add_key function in the keyring code in Linux kernel 2.6.16.1 and 2.6.17-rc1, and possibly earlier versions, allows local users to cause a denial of service (OOPS) via keyctl requests that add a key to a user key instead of a keyring key, which causes an invalid dereference in the __keyring_search_one function.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
http://support.avaya.com/elmodocs2/security/ASA-2006-161.htm
x_refsource_CONFIRM
RHSA-2006:0493
vendor-advisory
x_refsource_REDHAT
19735
third-party-advisory
x_refsource_SECUNIA
https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=188466
x_refsource_CONFIRM
linux-keyringsearchone-dos(25722)
vdb-entry
x_refsource_XF
20716
third-party-advisory
x_refsource_SECUNIA
FEDORA-2006-423
vendor-advisory
x_refsource_FEDORA
21745
third-party-advisory
x_refsource_SECUNIA
USN-302-1
vendor-advisory
x_refsource_UBUNTU
oval:org.mitre.oval:def:9325
vdb-entry
signature
x_refsource_OVAL
24507
vdb-entry
x_refsource_OSVDB
19573
third-party-advisory
x_refsource_SECUNIA
ADV-2006-1307
vdb-entry
x_refsource_VUPEN
17451
vdb-entry
x_refsource_BID
ADV-2006-1475
vdb-entry
x_refsource_VUPEN
http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.16.3
x_refsource_CONFIRM
20237
third-party-advisory
x_refsource_SECUNIA
MDKSA-2006:086
vendor-advisory
x_refsource_MANDRIVA
20157
third-party-advisory
x_refsource_SECUNIA
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now