CVE-2017-7472: Medium severity Linux Linux kernel vulnerability
A vulnerability was found in the Linux kernel. It was found that keyctlsetreqkeykeyring() function leaks thread keyring which allows unprivileged local user to exhaust kernel memory.
References:
https://lkml.org/lkml/2017/4/1/235
https://lkml.org/lkml/2017/4/3/724
http://seclists.org/oss-sec/2017/q2/246
Upstream patch:
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=c9f838d104fed6f2f61d68164712e3204bf5271b
Other sources
The KEYS subsystem in the Linux kernel before 4.10.13 allows local users to cause a denial of service (memory consumption) via a series of KEYREQKEYDEFLTHREADKEYRING keyctlsetreqkeykeyring calls.
— Launchpad
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the CVE ID of this vulnerability?
The CVE ID of this vulnerability is CVE-2017-7472.
What is the severity level of CVE-2017-7472?
The severity level of CVE-2017-7472 is medium (4 out of 10).
What is the affected software for CVE-2017-7472?
The affected software for CVE-2017-7472 includes various versions of the Linux kernel before 4.11~ in different distributions.
How does CVE-2017-7472 affect the system?
CVE-2017-7472 allows local users to cause a denial of service (memory consumption) via a series of keyctl_set_reqkey_keyring calls.
Are there any references for CVE-2017-7472?
Yes, you can find more information about CVE-2017-7472 at the following links: [Reference 1](https://lkml.org/lkml/2017/4/1/235), [Reference 2](https://lkml.org/lkml/2017/4/3/724), [Reference 3](http://seclists.org/oss-sec/2017/q2/246).