First published: Mon Apr 10 2006(Updated: )
The sys_add_key function in the keyring code in Linux kernel 2.6.16.1 and 2.6.17-rc1, and possibly earlier versions, allows local users to cause a denial of service (OOPS) via keyctl requests that add a key to a user key instead of a keyring key, which causes an invalid dereference in the __keyring_search_one function.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Linux kernel | =2.6.16.1 | |
Linux kernel | =2.6.17-rc1 | |
Linux Kernel | =2.6.16.1 | |
Linux Kernel | =2.6.17-rc1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-1522 is classified as a denial of service vulnerability in specific Linux kernel versions.
To mitigate CVE-2006-1522, upgrade to a patched version of the Linux kernel or apply available security updates.
CVE-2006-1522 affects Linux kernel versions 2.6.16.1 and 2.6.17-rc1, along with potentially earlier versions.
Local users can exploit CVE-2006-1522 to create a denial of service condition.
The impact of CVE-2006-1522 is a denial of service, leading to a system crash due to an invalid memory dereference.