Back to search
CVE-2017-12192
Published: Oct 12, 2017
Modified: Aug 5, 2024
PUBLISHED
Description
The keyctl_read_key function in security/keys/keyctl.c in the Key Management subcomponent in the Linux kernel before 4.13.5 does not properly consider that a key may be possessed but negatively instantiated, which allows local users to cause a denial of service (OOPS and system crash) via a crafted KEYCTL_READ operation.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
https://bugzilla.redhat.com/show_bug.cgi?id=1493435
x_refsource_CONFIRM
USN-3583-2
vendor-advisory
x_refsource_UBUNTU
http://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.13.5
x_refsource_CONFIRM
USN-3583-1
vendor-advisory
x_refsource_UBUNTU
RHSA-2018:0151
vendor-advisory
x_refsource_REDHAT
https://lkml.org/lkml/2017/9/18/764
x_refsource_MISC
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now