Name | CVE-2017-17807 |
Description | The KEYS subsystem in the Linux kernel before 4.14.6 omitted an access-control check when adding a key to the current task's "default request-key keyring" via the request_key() system call, allowing a local user to use a sequence of crafted system calls to add keys to a keyring with only Search permission (not Write permission) to that keyring, related to construct_get_dest_keyring() in security/keys/request_key.c. |
Source | CVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) |
References | DLA-1232-1, DSA-4073-1, DSA-4082-1 |
The table below lists information on source packages.
Source Package | Release | Version | Status |
---|---|---|---|
linux (PTS) | bullseye | 5.10.218-1 | fixed |
bullseye (security) | 5.10.221-1 | fixed | |
bookworm | 6.1.94-1 | fixed | |
bookworm (security) | 6.1.90-1 | fixed | |
trixie | 6.9.8-1 | fixed | |
sid | 6.9.9-1 | fixed |
The information below is based on the following data on fixed versions.
Package | Type | Release | Fixed Version | Urgency | Origin | Debian Bugs |
---|---|---|---|---|---|---|
linux | source | wheezy | 3.2.96-3 | DLA-1232-1 | ||
linux | source | jessie | 3.16.51-3+deb8u1 | DSA-4082-1 | ||
linux | source | stretch | 4.9.65-3+deb9u1 | DSA-4073-1 | ||
linux | source | (unstable) | 4.14.7-1 |
Fixed by: https://git.kernel.org/linus/4dca6ea1d9432052afb06baf2e3ae78188a4410b (v4.15-rc3)