CVE-2016-0728: Integer Overflow

Published Jan 11, 2016
·
Updated

It was reported that possible use-after-free vulnerability in keyring facility, possibly leading to local privilege escalation, was found. Function joinsessionkeyring in security/keys/processkeys.c holds a reference to the requested keyring, but if that keyring is the same as the one being currently used by the process, the kernel wouldn't decrease keyring->usage before returning to userspace. The usage field can be possibly overflowed causing use-after-free on the keyring object.

Introduced by: http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=3a50597de8635cd05133bd12c95681c82fe7b878

References: http://perception-point.io/2016/01/14/analysis-and-exploitation-of-a-linux-kernel-vulnerability-cve-2016-0728/

Red Hat KCS article: https://access.redhat.com/articles/2131021

Upstream patch: https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=23567fd052a9abb6d67fe8e7a9ccdd9800a540f2

Other sources

The joinsessionkeyring function in security/keys/processkeys.c in the Linux kernel before 4.4.1 mishandles object references in a certain error case, which allows local users to gain privileges or cause a denial of service (integer overflow and use-after-free) via crafted keyctl commands.

Affected Software

39 affected componentsFixes available
debian/linux
4.19.249-24.19.289-25.10.197-15.10.191-16.1.66-16.1.69-16.5.13-16.6.9-1
Google Android=4.0
Google Android=4.0.1
Google Android=4.0.2
Google Android=4.0.3
Google Android=4.0.4
Google Android=4.1
Google Android=4.1.2
Google Android=4.2
Google Android=4.2.1
Google Android=4.2.2
Google Android=4.3
Google Android=4.3.1
Google Android=4.4
Google Android=4.4.1
Google Android=4.4.2
Google Android=4.4.3
Google Android=5.0
Google Android=5.0.1
Google Android=5.0.2
Google Android=5.1
Google Android=5.1.0
Google Android=5.1.1
Google Android=6.0
Google Android=6.0.1
HP Server Migration Pack<=7.5
Linux Linux kernel>=3.8<3.10.95
Linux Linux kernel>=3.11<3.12.53
Linux Linux kernel>=3.13<3.14.59
Linux Linux kernel>=3.15<3.16.35
Linux Linux kernel>=3.17<3.18.26
Linux Linux kernel>=3.19<4.1.16
Linux Linux kernel>=4.2<4.3.4
Linux Linux kernel>=4.4<4.4.1
Debian Debian Linux=8.0
Canonical Ubuntu Linux=12.04
Canonical Ubuntu Linux=14.04
Canonical Ubuntu Linux=15.04
Canonical Ubuntu Linux=15.10

Event History

Jan 11, 2016
Data Sourced
03:42 PM
DescriptionSeverityAffected Software
Feb 8, 2016
CVE Published
via MITRE·02:00 AM
Data Sourced
via MITRE·02:00 AM
Description
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2016-0728?

CVE-2016-0728 has been classified as a high-severity vulnerability due to its capability to potentially lead to local privilege escalation.

2

How do I fix CVE-2016-0728?

Fix CVE-2016-0728 by upgrading your Linux kernel to the specified patched versions which include 4.19.249-2 or later.

3

Which versions of Linux are affected by CVE-2016-0728?

CVE-2016-0728 affects multiple versions of Linux, including certain releases of the Linux kernel prior to the patched versions.

4

Is there a workaround for CVE-2016-0728?

A direct workaround for CVE-2016-0728 is not recommended; the safest resolution is to update to a patched version.

5

What types of systems are impacted by CVE-2016-0728?

CVE-2016-0728 impacts systems running affected versions of the Linux kernel across various distributions, including Debian and Ubuntu.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203