NULL Pointer Dereference and System Crash Vulnerability in Linux Kernel's KEYS Subsystem

NULL Pointer Dereference and System Crash Vulnerability in Linux Kernel's KEYS Subsystem

CVE-2017-2647 · HIGH Severity

AV:L/AC:L/AU:N/C:C/I:C/A:C

The KEYS subsystem in the Linux kernel before 3.18 allows local users to gain privileges or cause a denial of service (NULL pointer dereference and system crash) via vectors involving a NULL value for a certain match field, related to the keyring_search_iterator function in keyring.c.

Learn more about our Cis Benchmark Audit For Distribution Independent Linux.