Back to search
CVE-2011-2184
Published: Sep 6, 2011
Modified: Aug 6, 2024
PUBLISHED
Description
The key_replace_session_keyring function in security/keys/process_keys.c in the Linux kernel before 2.6.39.1 does not initialize a certain structure member, which allows local users to cause a denial of service (NULL pointer dereference and OOPS) or possibly have unspecified other impact via a KEYCTL_SESSION_TO_PARENT argument to the keyctl function, a different vulnerability than CVE-2010-2960.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
[oss-security] 20110603 CVE request: kernel: set cred->user_ns in key_replace_session_keyring
mailing-list
x_refsource_MLIST
[linux-kernel] 20110524 Re: Fwd: Oops (bad memory deref) in slab_alloc() due to filp_cachep holding incorrect values
mailing-list
x_refsource_MLIST
[linux-kernel] 20110523 Oops (bad memory deref) in slab_alloc() due to filp_cachep holding incorrect values
mailing-list
x_refsource_MLIST
8371
third-party-advisory
x_refsource_SREASON
http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.39.1
x_refsource_CONFIRM
[oss-security] 20110606 Re: CVE request: kernel: set cred->user_ns in key_replace_session_keyring
mailing-list
x_refsource_MLIST
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now