CVE-2016-0728

CVSS v3.1 7.8 (High)
78% Progress
CVSS v2.0 7.2 (High)
72% Progress
EPSS 0.04 % (0th)
0.04% Progress
Affected Products 5
Advisories 30

The join_session_keyring function in security/keys/process_keys.c in the Linux kernel before 4.4.1 mishandles object references in a certain error case, which allows local users to gain privileges or cause a denial of service (integer overflow and use-after-free) via crafted keyctl commands.

Weaknesses
CWE-NVD-Other
Related CVEs
CVE Status
PUBLISHED
CNA
Red Hat, Inc.
Published Date
2016-02-08 03:59:10
(8 years ago)
Updated Date
2023-02-12 23:15:55
(19 months ago)

Affected Products

Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Google Android 4.0 cpe:2.3:o:google:android:4.0
  Google Android 4.0.1 cpe:2.3:o:google:android:4.0.1
  Google Android 4.0.2 cpe:2.3:o:google:android:4.0.2
  Google Android 4.0.3 cpe:2.3:o:google:android:4.0.3
  Google Android 4.0.4 cpe:2.3:o:google:android:4.0.4
  Google Android 4.1 cpe:2.3:o:google:android:4.1
  Google Android 4.1.2 cpe:2.3:o:google:android:4.1.2
  Google Android 4.2 cpe:2.3:o:google:android:4.2
  Google Android 4.2.1 cpe:2.3:o:google:android:4.2.1
  Google Android 4.2.2 cpe:2.3:o:google:android:4.2.2
  Google Android 4.3 cpe:2.3:o:google:android:4.3
  Google Android 4.3.1 cpe:2.3:o:google:android:4.3.1
  Google Android 4.4 cpe:2.3:o:google:android:4.4
  Google Android 4.4.1 cpe:2.3:o:google:android:4.4.1
  Google Android 4.4.2 cpe:2.3:o:google:android:4.4.2
  Google Android 4.4.3 cpe:2.3:o:google:android:4.4.3
  Google Android 5.0 cpe:2.3:o:google:android:5.0
  Google Android 5.0.1 cpe:2.3:o:google:android:5.0.1
  Google Android 5.0.2 cpe:2.3:o:google:android:5.0.2
  Google Android 5.1 cpe:2.3:o:google:android:5.1
  Google Android 5.1.0 cpe:2.3:o:google:android:5.1.0
  Google Android 5.1.1 cpe:2.3:o:google:android:5.1.1
  Google Android 6.0 cpe:2.3:o:google:android:6.0
  Google Android 6.0.1 cpe:2.3:o:google:android:6.0.1

Configuration #2

    CPE23 From Up To
  Hp Server Migration Pack 7.5 and prior versions cpe:2.3:a:hp:server_migration_pack <= 7.5

Configuration #3

    CPE23 From Up To
  Linux Kernel from 3.8 version and prior 3.10.95 version cpe:2.3:o:linux:linux_kernel >= 3.8 < 3.10.95
  Linux Kernel from 3.11 version and prior 3.12.53 version cpe:2.3:o:linux:linux_kernel >= 3.11 < 3.12.53
  Linux Kernel from 3.13 version and prior 3.14.59 version cpe:2.3:o:linux:linux_kernel >= 3.13 < 3.14.59
  Linux Kernel from 3.15 version and prior 3.16.35 version cpe:2.3:o:linux:linux_kernel >= 3.15 < 3.16.35
  Linux Kernel from 3.17 version and prior 3.18.26 version cpe:2.3:o:linux:linux_kernel >= 3.17 < 3.18.26
  Linux Kernel from 3.19 version and prior 4.1.16 version cpe:2.3:o:linux:linux_kernel >= 3.19 < 4.1.16
  Linux Kernel from 4.2 version and prior 4.3.4 version cpe:2.3:o:linux:linux_kernel >= 4.2 < 4.3.4
  Linux Kernel from 4.4 version and prior 4.4.1 version cpe:2.3:o:linux:linux_kernel >= 4.4 < 4.4.1

Configuration #4

    CPE23 From Up To
  Debian Linux 8.0 cpe:2.3:o:debian:debian_linux:8.0

Configuration #5

    CPE23 From Up To
  Canonical Ubuntu Linux 12.04 cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:-
  Canonical Ubuntu Linux 14.04 cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:esm
  Canonical Ubuntu Linux 15.04 cpe:2.3:o:canonical:ubuntu_linux:15.04
  Canonical Ubuntu Linux 15.10 cpe:2.3:o:canonical:ubuntu_linux:15.10
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...