CVE-2017-6951: Null Pointer Dereference
Last updated 24 July 2024
Other sources
The keyringsearchaux function in security/keys/keyring.c in the Linux kernel allows local users to cause a denial of service (NULL pointer dereference and OOPS) via a requestkey system call for the "dead" type.
References:
http://www.spinics.net/lists/keyrings/msg01846.html
Upstream patch:
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=c06cfb08b88d
— Red Hat
The keyringsearchaux function in security/keys/keyring.c in the Linux kernel allows local users to cause a denial of service via a requestkey system call for the "dead" key type.
The keyringsearchaux function in security/keys/keyring.c in the Linux kernel through 3.14.79 allows local users to cause a denial of service (NULL pointer dereference and OOPS) via a requestkey system call for the "dead" type.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/kernel-rtto a version that resolves this vulnerability.Fixed in 0:3.10.0-693.rt56.617.el7 - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 0:3.10.0-693.el7 - Upgrade
Upgrade
redhat/kernel-rtto a version that resolves this vulnerability.Fixed in 1:3.10.0-693.2.1.rt56.585.el6 - Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 5.10.223-1Fixed in 5.10.234-1Fixed in 6.1.129-1Fixed in 6.1.133-1Fixed in 6.12.21-1Fixed in 6.12.22-1 - Upgrade
Upgrade
linux kernelto a version that resolves this vulnerability.Patch c06cfb08b88d - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 3.14.79
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2017-6951.
What is the severity of CVE-2017-6951?
The severity of CVE-2017-6951 is medium with a CVSS score of 5.5.
What is the affected software?
The affected software includes Linux kernel versions up to 3.14.79.
How can this vulnerability be exploited?
This vulnerability can be exploited by local users to cause a denial of service (NULL pointer dereference and OOPS) via a request_key system call for the "dead" type.
Are there any references for CVE-2017-6951?
Yes, you can refer to the following links for more information: http://www.spinics.net/lists/keyrings/msg01846.html, https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=c06cfb08b88d, https://bugzilla.redhat.com/show_bug.cgi/attachment.cgi?id=1268882&action=diff