New Search

The sys_add_key function in the keyring code in Linux kernel 2.6.16.1 and 2.6.17-rc1 and possibly earlier versions allows local users to cause a denial of service (OOPS) via keyctl requests that add a key to a user key instead of a keyring key which causes an invalid dereference in the __keyring_search_one function.

oval:org.mitre.oval:def:9325

The sys_add_key function in the keyring code in Linux kernel 2.6.16.1 and 2.6.17-rc1 and possibly earlier versions allows local users to cause a denial of service (OOPS) via keyctl requests that add a key to a user key instead of a keyring key which causes an invalid dereference in the __keyring_search_one function.

Family:
unix
Status:
ACCEPTED
Platform(s):
  • Red Hat Enterprise Linux 4
  • Oracle Linux 4
  • CentOS Linux 4
Class:
vulnerability
Reference(s):
  • CVE-2006-1522
Product(s):