CVE-2016-4470
—CVSS 3.0
5.5 medium
EPSS
<1%p46
Published
()
Modified
Description
The key_reject_and_link function in security/keys/key.c in the Linux kernel through 4.6.3 does not ensure that a certain data structure is initialized, which allows local users to cause a denial of service (system crash) via vectors involving a crafted keyctl request2 command.
- Vendors
- oraclelinuxnovellredhat
- Products
- vm server, linux, linux kernel, suse linux enterprise real time extension, enterprise linux, enterprise linux desktop, enterprise linux for real time, enterprise linux hpc node, enterprise linux hpc node eus, enterprise linux server, enterprise linux server aus, enterprise linux server eus
- Vector
- CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
In the news0 stories
No ingested article mentions this CVE yet.