UBUNTU-CVE-2016-4470
The key_reject_and_link function in security/keys/key.c in the Linux kernel through 4.6.3 does not ensure that a certain data structure is initialized, which allows local users to cause a denial of service (system crash) via vectors involving a crafted keyctl request2 command.
02 / AFFECTED SOFTWARE
Affected packages
94 explicit affected versions
29 explicit affected versions
10 explicit affected versions
29 explicit affected versions
11 explicit affected versions
6 explicit affected versions
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
The key_reject_and_link function in security/keys/key.c in the Linux kernel through 4.6.3 does not ensure that a certain data structure is initialized, which allows local users to cause a denial of service (system crash) via vectors involving a crafted keyctl request2 command.
05 / REFERENCES
Further evidence
- https://ubuntu.com/security/CVE-2016-4470
- https://ubuntu.com/security/notices/USN-3049-1
- https://ubuntu.com/security/notices/USN-3050-1
- https://ubuntu.com/security/notices/USN-3051-1
- https://ubuntu.com/security/notices/USN-3052-1
- https://ubuntu.com/security/notices/USN-3053-1
- https://ubuntu.com/security/notices/USN-3054-1
- https://ubuntu.com/security/notices/USN-3055-1
- https://ubuntu.com/security/notices/USN-3056-1
- https://ubuntu.com/security/notices/USN-3057-1
- https://www.cve.org/CVERecord?id=CVE-2016-4470
- https://www.spinics.net/lists/linux-kernel-janitors/msg26069.html