CVE-2010-1437
HIGH severity · CVSS 7 · CWE-362
7CVSS HIGH
Summary
Race condition in the find_keyring_by_name function in security/keys/keyring.c in the Linux kernel 2.6.34-rc5 and earlier allows local users to cause a denial of service (memory corruption and system crash) or possibly have unspecified other impact via keyctl session commands that trigger access to a dead keyring that is undergoing deletion by the key_cleanup function.
Impact & exploitability
Attack vectorLocal
Attack complexityHigh
Privileges requiredLow
User interactionNone
Confidentiality impactHigh
Integrity impactHigh
Availability impactHigh
Exploit probability (EPSS)1%
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected products we track (1)
Recommendation
Apply the vendor fix promptly. Open any affected product above for its exact safe version.
Additional information
- NVD record
- http://lists.opensuse.org/opensuse-security-announce/2010-07/msg00006.html
- http://marc.info/?l=linux-kernel&m=127292492727029&w=2
- http://secunia.com/advisories/39830
- http://secunia.com/advisories/40218
- http://secunia.com/advisories/40645
- http://secunia.com/advisories/43315
- http://marc.info/?l=linux-kernel&m=127192182917857&w=2Exploit
- http://marc.info/?l=linux-kernel&m=127274294622730&w=2Exploit