VULNERABILITY INTELLIGENCE
CVE-2016-9604
CVSS score4.4 MEDIUM
EPSS probability0.27%
CISA KEVNot currently listed
Published2018-07-11
Last modified2026-06-17
CVSS vectorCVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N
Description
It was discovered in the Linux kernel before 4.11-rc8 that root can gain direct access to an internal keyring, such as '.dns_resolver' in RHEL-7 or '.builtin_trusted_keys' upstream, by joining it as its session keyring. This allows root to bypass module signature verification by adding a new public key of its own devising to the keyring.
Weakness classification
- CWE-347: Improper Verification of Cryptographic Signature
- CWE-732: Incorrect Permission Assignment for Critical Resource
Primary references
- secalert@redhat.com — Third Party Advisory
- secalert@redhat.com — Third Party Advisory, VDB Entry
- secalert@redhat.com — Third Party Advisory
- secalert@redhat.com — Third Party Advisory
- secalert@redhat.com — Third Party Advisory
- secalert@redhat.com — Issue Tracking, Third Party Advisory
- secalert@redhat.com — Issue Tracking, Third Party Advisory
- secalert@redhat.com — Patch, Vendor Advisory
- af854a3a-2127-422b-91ae-364da2661108 — Third Party Advisory
- af854a3a-2127-422b-91ae-364da2661108 — Third Party Advisory, VDB Entry
- af854a3a-2127-422b-91ae-364da2661108 — Third Party Advisory
- af854a3a-2127-422b-91ae-364da2661108 — Third Party Advisory