The keyring_detect_cycle_iterator function in security/keys/keyring.c in the Linux kernel through 3.13.6 does not properly determine whether keyrings are identical, which allows local users to cause a denial of service (OOPS) via crafted keyctl commands.
CVSS Details
- CVSS 3.1 Base Score: 5.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade linux | Jul 30, 2024 | Mar 11, 2014 |
| Suse | — | Upgrade kernel-defaultUpgrade kernel-obs-buildUpgrade kernel-docsUpgrade kernel-zfcpdump | Dec 9, 2016 | Mar 11, 2014 |
| Ubuntu | — | Upgrade linux-raspi2 | Nov 19, 2024 | Mar 11, 2014 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub