ZeroHour

CVE-2016-4470

CVSS 3.0
5.5 medium
EPSS
<1%p46
Published
()
Modified
Description

The key_reject_and_link function in security/keys/key.c in the Linux kernel through 4.6.3 does not ensure that a certain data structure is initialized, which allows local users to cause a denial of service (system crash) via vectors involving a crafted keyctl request2 command.

Vendors
oraclelinuxnovellredhat
Products
vm server, linux, linux kernel, suse linux enterprise real time extension, enterprise linux, enterprise linux desktop, enterprise linux for real time, enterprise linux hpc node, enterprise linux hpc node eus, enterprise linux server, enterprise linux server aus, enterprise linux server eus
Vector
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.