CVE-2017-2647

The KEYS subsystem in the Linux kernel before 3.18 allows local users to gain privileges or cause a denial of service (NULL pointer dereference and system crash) via vectors involving a NULL value for a certain match field, related to the keyring_search_iterator function in keyring.c.
Configurations

Configuration 1 (hide)

cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

History

12 Feb 2023, 23:29

Type Values Removed Values Added
References
  • {'url': 'https://access.redhat.com/errata/RHSA-2020:3548', 'name': 'https://access.redhat.com/errata/RHSA-2020:3548', 'tags': [], 'refsource': 'MISC'}
  • {'url': 'https://access.redhat.com/errata/RHSA-2020:3836', 'name': 'https://access.redhat.com/errata/RHSA-2020:3836', 'tags': [], 'refsource': 'MISC'}
  • {'url': 'https://access.redhat.com/security/cve/CVE-2017-2647', 'name': 'https://access.redhat.com/security/cve/CVE-2017-2647', 'tags': [], 'refsource': 'MISC'}
Summary A flaw was found that can be triggered in keyring_search_iterator in keyring.c if type->match is NULL. A local user could use this flaw to crash the system or, potentially, escalate their privileges. The KEYS subsystem in the Linux kernel before 3.18 allows local users to gain privileges or cause a denial of service (NULL pointer dereference and system crash) via vectors involving a NULL value for a certain match field, related to the keyring_search_iterator function in keyring.c.

02 Feb 2023, 21:17

Type Values Removed Values Added
References
  • (MISC) https://access.redhat.com/errata/RHSA-2020:3548 -
  • (MISC) https://access.redhat.com/errata/RHSA-2020:3836 -
  • (MISC) https://access.redhat.com/security/cve/CVE-2017-2647 -
Summary The KEYS subsystem in the Linux kernel before 3.18 allows local users to gain privileges or cause a denial of service (NULL pointer dereference and system crash) via vectors involving a NULL value for a certain match field, related to the keyring_search_iterator function in keyring.c. A flaw was found that can be triggered in keyring_search_iterator in keyring.c if type->match is NULL. A local user could use this flaw to crash the system or, potentially, escalate their privileges.

Information

Published : 2017-03-31 04:59

Updated : 2023-12-10 12:01


NVD link : CVE-2017-2647

Mitre link : CVE-2017-2647

CVE.ORG link : CVE-2017-2647


JSON object : View

Products Affected

linux

  • linux_kernel
CWE
CWE-476

NULL Pointer Dereference