CVE-2015-7550 PUBLISHED

The keyctl_read_key function in security/keys/keyctl.c in the Linux kernel before 4.3.4 does not properly use a semaphore, which allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact via a crafted application that leverages a race condition between keyctl_revoke and keyctl_read calls.

EPSS 0.05% · 15.5th percentile

Risk Scores

EPSS Score
0.05%
15.5th percentile

Affected Products

VendorProductVersions
Ubuntu:20.04:LTSlinux-azure-fde5.4.0-1068.71+cvm1.1, 5.4.0-1067.70+cvm1.1, 5.4.0-1065.68+cvm2.1
Ubuntu:20.04:LTSlinux-gkeop5.4.0-1075.79, 5.4.0-1074.78, 5.4.0-1073.77
Ubuntu:22.04:LTSlinux-intel-iot-realtime0, 5.15.0-1073.75
Ubuntu:18.04:LTSlinux-hwe-edge5.0.0-20.21~18.04.1, 5.0.0-19.20~18.04.1, 5.0.0-17.18~18.04.1
Ubuntu:20.04:LTSlinux-riscv5.4.0-27.31, 5.4.0-30.34, 5.4.0-31.35
Ubuntu:18.04:LTSlinux-azure5.0.0-1025.27~18.04.1, 0, 4.15.0-1002.2
Ubuntu:20.04:LTSlinux-gke5.4.0-1080.86, 5.4.0-1078.84, 5.4.0-1076.82
Ubuntu:14.04:LTSlinux-lts-utopic3.16.0-33.44~14.04.1, 3.16.0-31.41~14.04.1, 3.16.0-30.40~14.04.1
Ubuntu:14.04:LTSlinux-lts-wily0, 4.2.0-18.22~14.04.1, 4.2.0-19.23~14.04.1
Ubuntu:14.04:LTSlinux-lts-vivid3.19.0-49.55~14.04.1, 3.19.0-33.38~14.04.1, 3.19.0-37.42~14.04.1
Ubuntu:20.04:LTSlinux-raspi25.3.0-1017.19, 5.3.0-1015.17, 5.3.0-1014.16
Ubuntu:22.04:LTSlinux-riscv5.15.0-1008.8, 0, 5.13.0-1004.4
Ubuntu:18.04:LTSlinux-gcp0, 4.15.0-1001.1, 4.15.0-1003.3
Ubuntu:Pro:20.04:LTSlinux-azure-fde-5.155.15.0-1087.96~20.04.1.1, 5.15.0-1088.97~20.04.1.1, 5.15.0-1089.98~20.04.1.1
Ubuntu:24.04:LTSlinux-realtime6.8.1-1015.16, 0
Ubuntu:24.04:LTSlinux-hwe-6.116.11.0-17.17~24.04.2, 6.11.0-24.24~24.04.1, 6.11.0-21.21~24.04.1
Ubuntu:24.04:LTSlinux-riscv6.8.0-49.49.1, 6.8.0-48.48.1, 6.8.0-47.47.1
Ubuntu:18.04:LTSlinux-hwe4.18.0-13.14~18.04.1, 4.18.0-14.15~18.04.1, 4.18.0-15.16~18.04.1
Ubuntu:24.04:LTSlinux-azure-6.110, 6.11.0-1008.8~24.04.1, 6.11.0-1012.12~24.04.1
Ubuntu:14.04:LTSlinux3.13.0-8.27, 3.13.0-7.25, 3.13.0-6.23

…and 4 more

Timeline

References

Open in Interactive Console →