CVE Vulnerabilities

CVE-2016-9604

Improper Verification of Cryptographic Signature

Published: Jul 11, 2018 | Modified: Nov 07, 2023
CVSS 3.x
4.4
MEDIUM
Source:
NVD
CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N
CVSS 2.x
2.1 LOW
AV:L/AC:L/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu

It was discovered in the Linux kernel before 4.11-rc8 that root can gain direct access to an internal keyring, such as .dns_resolver in RHEL-7 or .builtin_trusted_keys upstream, by joining it as its session keyring. This allows root to bypass module signature verification by adding a new public key of its own devising to the keyring.

Weakness

The product does not verify, or incorrectly verifies, the cryptographic signature for data.

Affected Software

Name Vendor Start Version End Version
Linux_kernel Linux * 4.11 (including)
Linux_kernel Linux 4.11-rc1 (including) 4.11-rc1 (including)
Linux_kernel Linux 4.11-rc2 (including) 4.11-rc2 (including)
Linux_kernel Linux 4.11-rc3 (including) 4.11-rc3 (including)
Linux_kernel Linux 4.11-rc4 (including) 4.11-rc4 (including)
Linux_kernel Linux 4.11-rc5 (including) 4.11-rc5 (including)
Linux_kernel Linux 4.11-rc6 (including) 4.11-rc6 (including)
Linux_kernel Linux 4.11-rc7 (including) 4.11-rc7 (including)

References