The keyring_search_aux function in security/keys/keyring.c in the Linux kernel through 3.14.79 allows local users to cause a denial of service (NULL pointer dereference and OOPS) via a request_key system call for the "dead" type.
The product dereferences a pointer that it expects to be valid but is NULL.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/96943 | vdb entry third party advisory |
https://access.redhat.com/errata/RHSA-2017:2669 | vendor advisory |
http://www.spinics.net/lists/keyrings/msg01849.html | third party advisory mailing list |
http://www.spinics.net/lists/keyrings/msg01845.html | third party advisory mailing list |
https://access.redhat.com/errata/RHSA-2017:2077 | vendor advisory |
https://access.redhat.com/errata/RHSA-2017:1842 | vendor advisory |
http://www.spinics.net/lists/keyrings/msg01846.html | third party advisory mailing list |