vendor:
Linux Kernel
by:
Sergej Schumilo, Ralf Spenneberg, Hendrik Schwartke
9
CVSS
CRITICAL
Local unprivileged kernel nullpointer dereference
476
CWE
Product Name: Linux Kernel
Affected Version From: Ubuntu Server 16.10 (GNU/Linux 4.8.0-22-generic x86_64)
Affected Version To: RedHat Kernel 3.10.0-327.18.2.el7.x86_64
Patch Exists: NO
Related CWE: Not yet assigned
CPE: o:linux:linux_kernel:4.8.0-22-generic
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Ubuntu Server, RedHat
2016
Local DoS: Linux Kernel Nullpointer Dereference via keyctl
A malicious interaction with the keyctl usermode interface allows an attacker to crash the kernel. Processing the attached certificate by the kernel leads to a kernel nullpointer dereference. This vulnerably can be triggered by any unprivileged user locally.
Mitigation:
Contact the vendor for a security patch.