CVE-2016-9604: Medium severity linux kernel vulnerability
It was discovered in the Linux kernel before 4.11-rc8 that root can gain direct access to an internal keyring, such as '.dnsresolver' in RHEL-7 or '.builtintrustedkeys' upstream, by joining it as its session keyring. This allows root to bypass module signature verification by adding a new public key of its own devising to the keyring.
Other sources
It was found that it is possible for root to gain direct access to an internal keyring, such as '.dnsresolver' in RHEL-7 or '.builtintrustedkeys' upstream, by joining it as its session keyring. This allows root to bypass module signature verification by adding a new public key of its own devising to the keyring.
References:
https://bugzilla.novell.com/showbug.cgi?id=1035576
http://people.canonical.com/~ubuntu-security/cve/2016/CVE-2016-9604.html
Upstream patch:
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=ee8f844e3c5a73b999edf733df1c529d6503ec2f
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2016-9604?
The severity of CVE-2016-9604 is low.
How can an attacker exploit CVE-2016-9604?
An attacker can exploit CVE-2016-9604 by joining an internal keyring as its session keyring.
Which Linux kernels are affected by CVE-2016-9604?
Linux kernels before 4.11-rc8 are affected by CVE-2016-9604.
Is there a fix for CVE-2016-9604?
Yes, updating the Linux kernel to version 4.11-rc8 or later will fix CVE-2016-9604.
Where can I find more information about CVE-2016-9604?
You can find more information about CVE-2016-9604 in the references provided: http://people.canonical.com/~ubuntu-security/cve/2016/CVE-2016-9604.html, https://bugzilla.novell.com/show_bug.cgi?id=1035576, https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-9604