Oval Definition:oval:com.ubuntu.artful:def:20169604000
Revision Date:2018-07-11Version:1
Title:CVE-2016-9604 on Ubuntu 17.10 (artful) - medium.
Description:It was discovered in the Linux kernel before 4.11-rc8 that root can gain direct access to an internal keyring, such as '.dns_resolver' in RHEL-7 or '.builtin_trusted_keys' upstream, by joining it as its session keyring. This allows root to bypass module signature verification by adding a new public key of its own devising to the keyring. It was discovered that the keyring implementation in the Linux kernel in some situations did not prevent special internal keyrings from being joined by userspace keyrings. A privileged local attacker could use this to bypass module verification.
Family:unixClass:vulnerability
Status:Reference(s):CVE-2016-9604
Platform(s):Ubuntu 17.10
Product(s):
Definition Synopsis
  • Ubuntu 17.10 (artful) is installed.
  • AND Package Information
  • NOT While related to the CVE in some way, the 'linux' package in artful is not affected (note: '4.10.0-22.24').
  • OR NOT While related to the CVE in some way, the 'linux-raspi2' package in artful is not affected (note: '4.10.0-1006.8').
  • OR NOT While related to the CVE in some way, the 'linux-snapdragon' package in artful is not affected (note: '4.4.0-1059.63').
  • BACK