Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The KEYS subsystem in the Linux kernel before 4.14.6 omitted an access-control check when adding a key to the current task's "default request-key keyring" via the request_key() system call, allowing a local user to use a sequence of crafted system calls to add keys to a keyring with only Search permission (not Write permission) to that keyring, related to construct_get_dest_keyring() in security/keys/request_key.c.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Linux kernel KEYS子系统安全漏洞
Vulnerability Description
Linux kernel是美国Linux基金会发布的开源操作系统Linux所使用的内核。KEYS subsystem是其中的一套密钥子系统。 Linux kernel 4.14.6之前的版本中的KEYS子系统存在安全漏洞,该漏洞源于程序没有进程访问控制检测。本地攻击者可利用该漏洞将密钥添加到只有搜索权限的密钥环中。
CVSS Information
N/A
Vulnerability Type
N/A