First published: Mon Nov 23 2015(Updated: )
A flaw was found in the Linux kernels key management system where it was possible for an attacker to escalate privileges or crash the machine. If a user key gets negatively instantiated, an error code is cached in the payload area. A negatively instantiated key may be then be positively instantiated by updating it with valid data. However, the ->update key type method must be aware that the error code may be there. Key management subsystems can abused to escalate privileges through memory corruption. Upstream: <a href="https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=096fe9eaea40a17e125569f9e657e34cdb6d73bd">https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=096fe9eaea40a17e125569f9e657e34cdb6d73bd</a>
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/kernel-rt | <0:3.10.0-693.17.1.rt56.636.el7 | 0:3.10.0-693.17.1.rt56.636.el7 |
redhat/kernel | <0:3.10.0-693.17.1.el7 | 0:3.10.0-693.17.1.el7 |
redhat/kernel-rt | <1:3.10.0-693.17.1.rt56.604.el6 | 1:3.10.0-693.17.1.rt56.604.el6 |
Canonical Ubuntu Linux | =12.04 | |
Canonical Ubuntu Linux | =14.04 | |
Suse Linux Enterprise Real Time Extension | =12-sp1 | |
Linux Linux kernel | <4.4 | |
Linux Linux kernel | =4.4-rc1 | |
Linux Linux kernel | =4.4-rc2 | |
debian/linux | 5.10.223-1 5.10.226-1 6.1.106-3 6.1.112-1 6.11.5-1 6.11.6-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
CVE-2015-8539 is a vulnerability in the Linux kernel that allows local users to gain privileges or crash the machine.
CVE-2015-8539 has a severity score of 7, which is considered high.
The Linux kernel versions before 4.4 are affected by CVE-2015-8539.
To fix CVE-2015-8539, update your Linux kernel to version 4.4~ or later.
You can find more information about CVE-2015-8539 at the following references: [Link 1](https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=096fe9eaea40a17e125569f9e657e34cdb6d73bd), [Link 2](https://access.redhat.com/security/cve/CVE-2015-8539), [Link 3](http://seclists.org/oss-sec/2015/q4/465).