CVE: CVE-2009-3624

Export to Word

The get_instantiation_keyring function in security/keys/keyctl.c in the KEYS subsystem in the Linux kernel before 2.6.32-rc5 does not properly maintain the reference count of a keyring, which allows local users to gain privileges or cause a denial of service (OOPS) via vectors involving calls to this function without specifying a keyring by ID, as demonstrated by a series of keyctl request2 and keyctl list commands.

Threat-Mapped Scoring

Score: 1.5

Priority: P4 - Informational (Low)

EPSS

Score: 0.00063
Percentile: 0.20095

CVSS Scoring

CVSS v2 Score: 4.6

Severity:

Affected Products

← Back to Home