CVE-2015-8539
moderate-risk
Published 2016-02-08
The KEYS subsystem in the Linux kernel before 4.4 allows local users to gain privileges or cause a denial of service (BUG) via crafted keyctl commands that negatively instantiate a key, related to security/keys/encrypted-keys/encrypted.c, security/keys/trusted.c, and security/keys/user_defined.c.
Do I need to act?
-
0.07% chance of exploitation
EPSS score — low exploit probability
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
7
CVSS 7.8/10
High
LOCAL
/ LOW complexity
Affected Products (6)
References (48)
Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00007.html
Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00008.html
Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00009.html
Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00011.html
Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00017.html
Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00018.html
Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00019.html
Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00020.html
Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00021.html
Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00022.html
Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00034.html
Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00094.html
Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00045.html
Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00000.html
Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00038.html
Issue Tracking
http://www.openwall.com/lists/oss-security/2015/12/09/1
Third Party Advisory
https://access.redhat.com/errata/RHSA-2018:0151
Third Party Advisory
https://access.redhat.com/errata/RHSA-2018:0152
Third Party Advisory
https://access.redhat.com/errata/RHSA-2018:0181
and 28 more references
37
/ 100
moderate-risk
Severity
24/34 · High
Exploitability
0/34 · Minimal
Exposure
13/34 · Low