The join_session_keyring function in security/keys/process_keys.c in the Linux kernel before 4.4.1 mishandles object references in a certain error case, which allows local users to gain privileges or cause a denial of service (integer overflow and use-after-free) via crafted keyctl commands.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Android | 5.1.0 | 5.1.0 | |
Android | 4.2 | 4.2 | |
Android | 4.1 | 4.1 | |
Android | 5.0.2 | 5.0.2 | |
Android | 6.0.1 | 6.0.1 | |
Android | 6.0 | 6.0 | |
Android | 4.0.2 | 4.0.2 | |
Android | 4.4.3 | 4.4.3 | |
Android | 4.0.4 | 4.0.4 | |
Android | 4.3 | 4.3 | |
Android | 4.0.1 | 4.0.1 | |
Android | 4.2.1 | 4.2.1 | |
Android | 5.0.1 | 5.0.1 | |
Android | 5.0 | 5.0 | |
Android | 4.0.3 | 4.0.3 | |
Android | 4.0 | 4.0 | |
Android | 4.4 | 4.4 | |
Android | 4.4.1 | 4.4.1 | |
Android | 5.1.1 | 5.1.1 | |
Android | 4.2.2 | 4.2.2 | |
Android | 4.3.1 | 4.3.1 | |
Android | 4.4.2 | 4.4.2 | |
Android | 5.1 | 5.1 | |
Android | 4.1.2 | 4.1.2 |