The keyctl_session_to_parent function in security/keys/keyctl.c in the Linux kernel 2.6.35.4 and earlier expects that a certain parent session keyring exists, which allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact via a KEYCTL_SESSION_TO_PARENT argument to the keyctl function.
The product dereferences a pointer that it expects to be valid but is NULL.
| Name | Vendor | Start Version | End Version | 
|---|---|---|---|
| Linux_kernel | Linux | * | 2.6.35.4 (excluding) | 
| Linux | Ubuntu | lucid | * | 
| Linux-ec2 | Ubuntu | karmic | * | 
| Linux-ec2 | Ubuntu | lucid | * | 
| Linux-ec2 | Ubuntu | maverick | * | 
| Linux-lts-backport-maverick | Ubuntu | lucid | * | 
| Linux-mvl-dove | Ubuntu | karmic | * | 
| Linux-mvl-dove | Ubuntu | lucid | * | 
| Linux-mvl-dove | Ubuntu | maverick | * | 
| Linux-ti-omap4 | Ubuntu | maverick | * |