R
ace condition in the find_keyring_by_name function in security/keys/keyring.c in the Linux kernel 2.6.34-rc5 and earlier allows local users to cause a denial of service (memory corruption and system crash) or possibly have unspecified other impact via keyctl session commands that trigger access to a dead keyring that is undergoing deletion by the key_cleanup function.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
History
21 Nov 2024, 01:14
| Type | Values Removed | Values Added |
|---|---|---|
| References | () http://lists.opensuse.org/opensuse-security-announce/2010-07/msg00006.html - Mailing List | |
| References | () http://marc.info/?l=linux-kernel&m=127192182917857&w=2 - Exploit, Mailing List | |
| References | () http://marc.info/?l=linux-kernel&m=127274294622730&w=2 - Exploit, Mailing List | |
| References | () http://marc.info/?l=linux-kernel&m=127292492727029&w=2 - Mailing List | |
| References | () http://secunia.com/advisories/39830 - Broken Link | |
| References | () http://secunia.com/advisories/40218 - Broken Link | |
| References | () http://secunia.com/advisories/40645 - Broken Link | |
| References | () http://secunia.com/advisories/43315 - Broken Link | |
| References | () http://www.debian.org/security/2010/dsa-2053 - Mailing List | |
| References | () http://www.openwall.com/lists/oss-security/2010/04/27/2 - Mailing List | |
| References | () http://www.openwall.com/lists/oss-security/2010/04/28/2 - Mailing List | |
| References | () http://www.redhat.com/support/errata/RHSA-2010-0474.html - Broken Link | |
| References | () http://www.securityfocus.com/archive/1/516397/100/0/threaded - Broken Link, Third Party Advisory, VDB Entry | |
| References | () http://www.securityfocus.com/bid/39719 - Broken Link, Third Party Advisory, VDB Entry | |
| References | () http://www.vmware.com/security/advisories/VMSA-2011-0003.html - Third Party Advisory | |
| References | () http://www.vupen.com/english/advisories/2010/1857 - Broken Link | |
| References | () https://bugzilla.redhat.com/show_bug.cgi?id=585094 - Exploit, Issue Tracking, Patch | |
| References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/58254 - Third Party Advisory, VDB Entry | |
| References | () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9715 - Broken Link | |
| References | () https://patchwork.kernel.org/patch/94038/ - Broken Link | |
| References | () https://patchwork.kernel.org/patch/94664/ - Broken Link, Patch |
Information
Published : 2010-05-07 18:30
Updated : 2025-04-11 00:51
NVD link : CVE-2010-1437
Mitre link : CVE-2010-1437
CVE.ORG link : CVE-2010-1437
JSON object : View
Products Affected