The KEYS subsystem in the Linux kernel before 4.4 allows local users to gain privileges or cause a denial of service (BUG) via crafted keyctl commands that negatively instantiate a key, related to security/keys/encrypted-keys/encrypted.c, security/keys/trusted.c, and security/keys/user_defined.c.
| Software | From | Fixed in |
|---|---|---|
| suse / linux_enterprise_real_time_extension | 12-sp1 | 12-sp1.x |
| canonical / ubuntu_linux | 14.04 | 14.04.x |
| canonical / ubuntu_linux | 12.04 | 12.04.x |
| linux / linux_kernel | 4.4-rc2 | 4.4-rc2.x |
| linux / linux_kernel | 4.4-rc1 | 4.4-rc1.x |
| linux / linux_kernel | - | 4.4 |