CVE
- Id
- 87024
- CVE No.
- CVE-2016-0728
- Status
- Candidate
- Description
- The join_session_keyring function in security/keys/process_keys.c in the Linux kernel before 4.4.1 mishandles object references in a certain error case, which allows local users to gain privileges or cause a denial of service (integer overflow and use-after-free) via crafted keyctl commands.
- Phase
- Assigned (20151216)
- Votes
- None (candidate not yet proposed)
- Comments
Related CVE References
Id | CVE Id | CVE No. | Reference | Actions |
---|---|---|---|---|
761688 | 87024 | CVE-2016-0728 | EXPLOIT-DB:39277 | View |
761689 | 87024 | CVE-2016-0728 | URL:https://www.exploit-db.com/exploits/39277/ | View |
761690 | 87024 | CVE-2016-0728 | MLIST:[oss-security] 20160119 Linux kernel: use after free in keyring facility. | View |
761691 | 87024 | CVE-2016-0728 | URL:http://www.openwall.com/lists/oss-security/2016/01/19/2 | View |
761692 | 87024 | CVE-2016-0728 | MISC:http://perception-point.io/2016/01/14/analysis-and-exploitation-of-a-linux-kernel-vulnerability-cve-2016-0728/ | View |
761693 | 87024 | CVE-2016-0728 | CONFIRM:http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=23567fd052a9abb6d67fe8e7a9ccdd9800a540f2 | View |
761694 | 87024 | CVE-2016-0728 | CONFIRM:http://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.4.1 | View |
761695 | 87024 | CVE-2016-0728 | CONFIRM:https://bugzilla.redhat.com/show_bug.cgi?id=1297475 | View |
761696 | 87024 | CVE-2016-0728 | CONFIRM:https://github.com/torvalds/linux/commit/23567fd052a9abb6d67fe8e7a9ccdd9800a540f2 | View |
761697 | 87024 | CVE-2016-0728 | CONFIRM:http://source.android.com/security/bulletin/2016-03-01.html | View |
761698 | 87024 | CVE-2016-0728 | CONFIRM:https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05130958 | View |
761699 | 87024 | CVE-2016-0728 | CONFIRM:https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05158380 | View |
761700 | 87024 | CVE-2016-0728 | CONFIRM:http://www.oracle.com/technetwork/topics/security/linuxbulletinjan2016-2867209.html | View |
761701 | 87024 | CVE-2016-0728 | CONFIRM:https://bto.bluecoat.com/security-advisory/sa112 | View |
761702 | 87024 | CVE-2016-0728 | DEBIAN:DSA-3448 | View |
761703 | 87024 | CVE-2016-0728 | URL:http://www.debian.org/security/2016/dsa-3448 | View |
761704 | 87024 | CVE-2016-0728 | FEDORA:FEDORA-2016-5d43766e33 | View |
761705 | 87024 | CVE-2016-0728 | URL:http://lists.fedoraproject.org/pipermail/package-announce/2016-February/176484.html | View |
761706 | 87024 | CVE-2016-0728 | FEDORA:FEDORA-2016-b59fd603be | View |
761707 | 87024 | CVE-2016-0728 | URL:http://lists.fedoraproject.org/pipermail/package-announce/2016-January/176194.html | View |
761708 | 87024 | CVE-2016-0728 | HP:HPSBHF03436 | View |
761709 | 87024 | CVE-2016-0728 | URL:https://h20565.www2.hp.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05018265 | View |
761710 | 87024 | CVE-2016-0728 | REDHAT:RHSA-2016:0064 | View |
761711 | 87024 | CVE-2016-0728 | URL:http://rhn.redhat.com/errata/RHSA-2016-0064.html | View |
761712 | 87024 | CVE-2016-0728 | REDHAT:RHSA-2016:0065 | View |
761713 | 87024 | CVE-2016-0728 | URL:http://rhn.redhat.com/errata/RHSA-2016-0065.html | View |
761714 | 87024 | CVE-2016-0728 | REDHAT:RHSA-2016:0068 | View |
761715 | 87024 | CVE-2016-0728 | URL:http://rhn.redhat.com/errata/RHSA-2016-0068.html | View |
761716 | 87024 | CVE-2016-0728 | SUSE:SUSE-SU-2016:0745 | View |
761717 | 87024 | CVE-2016-0728 | URL:http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00033.html | View |
761718 | 87024 | CVE-2016-0728 | SUSE:SUSE-SU-2016:0746 | View |
761719 | 87024 | CVE-2016-0728 | URL:http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00034.html | View |
761720 | 87024 | CVE-2016-0728 | SUSE:SUSE-SU-2016:0747 | View |
761721 | 87024 | CVE-2016-0728 | URL:http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00035.html | View |
761722 | 87024 | CVE-2016-0728 | SUSE:SUSE-SU-2016:0750 | View |
761723 | 87024 | CVE-2016-0728 | URL:http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00038.html | View |
761724 | 87024 | CVE-2016-0728 | SUSE:SUSE-SU-2016:0751 | View |
761725 | 87024 | CVE-2016-0728 | URL:http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00039.html | View |
761726 | 87024 | CVE-2016-0728 | SUSE:SUSE-SU-2016:0752 | View |
761727 | 87024 | CVE-2016-0728 | URL:http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00040.html | View |
761728 | 87024 | CVE-2016-0728 | SUSE:SUSE-SU-2016:0753 | View |
761729 | 87024 | CVE-2016-0728 | URL:http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00041.html | View |
761730 | 87024 | CVE-2016-0728 | SUSE:SUSE-SU-2016:0755 | View |
761731 | 87024 | CVE-2016-0728 | URL:http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00043.html | View |
761732 | 87024 | CVE-2016-0728 | SUSE:SUSE-SU-2016:0756 | View |
761733 | 87024 | CVE-2016-0728 | URL:http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00044.html | View |
761734 | 87024 | CVE-2016-0728 | SUSE:SUSE-SU-2016:0757 | View |
761735 | 87024 | CVE-2016-0728 | URL:http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00045.html | View |
761736 | 87024 | CVE-2016-0728 | SUSE:SUSE-SU-2016:0205 | View |
761737 | 87024 | CVE-2016-0728 | URL:http://lists.opensuse.org/opensuse-security-announce/2016-01/msg00026.html | View |
761738 | 87024 | CVE-2016-0728 | SUSE:SUSE-SU-2016:0341 | View |
761739 | 87024 | CVE-2016-0728 | URL:http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00012.html | View |
761740 | 87024 | CVE-2016-0728 | UBUNTU:USN-2870-1 | View |
761741 | 87024 | CVE-2016-0728 | URL:http://www.ubuntu.com/usn/USN-2870-1 | View |
761742 | 87024 | CVE-2016-0728 | UBUNTU:USN-2870-2 | View |
761743 | 87024 | CVE-2016-0728 | URL:http://www.ubuntu.com/usn/USN-2870-2 | View |
761744 | 87024 | CVE-2016-0728 | UBUNTU:USN-2871-1 | View |
761745 | 87024 | CVE-2016-0728 | URL:http://www.ubuntu.com/usn/USN-2871-1 | View |
761746 | 87024 | CVE-2016-0728 | UBUNTU:USN-2871-2 | View |
761747 | 87024 | CVE-2016-0728 | URL:http://www.ubuntu.com/usn/USN-2871-2 | View |
761748 | 87024 | CVE-2016-0728 | UBUNTU:USN-2872-1 | View |
761749 | 87024 | CVE-2016-0728 | URL:http://www.ubuntu.com/usn/USN-2872-1 | View |
761750 | 87024 | CVE-2016-0728 | UBUNTU:USN-2872-2 | View |
761751 | 87024 | CVE-2016-0728 | URL:http://www.ubuntu.com/usn/USN-2872-2 | View |
761752 | 87024 | CVE-2016-0728 | UBUNTU:USN-2872-3 | View |
761753 | 87024 | CVE-2016-0728 | URL:http://www.ubuntu.com/usn/USN-2872-3 | View |
761754 | 87024 | CVE-2016-0728 | UBUNTU:USN-2873-1 | View |
761755 | 87024 | CVE-2016-0728 | URL:http://www.ubuntu.com/usn/USN-2873-1 | View |
761756 | 87024 | CVE-2016-0728 | BID:81054 | View |
Related JVN
Id | JVN No. | Title | Summary | CVE No. | CVE Id | CVSS_v2 | CVSS_v3 | JVN URL | Actions |
---|---|---|---|---|---|---|---|---|---|
1024 | JVNDB-2016-001797 | Android の MediaTek Wi-Fi カーネルドライバにおける権限を取得される脆弱性 | Android の MediaTek Wi-Fi カーネルドライバには、権限を取得される脆弱性が存在します。 | CVE-2016-0820 | 87024 | 9.3 | http://jvndb.jvn.jp/ja/contents/2016/JVNDB-2016-001797.html | View |