CVE-2015-8970
개요
The lrw_crypt() function in 'crypto/lrw.c' in the Linux kernel before 4.5 allows local users to cause a system crash and a denial of service by the NULL pointer dereference via accept(2) system call for AF_ALG socket without calling setkey() first to set a cipher key.
내용
This issue does not affect the Linux kernel packages as shipped with Red Hat Enterprise Linux 5, 6 as the code with the flaw is not present in the products listed.
This issue affects the Linux kernel packages as shipped with Red Hat Enterprise Linux 7 and MRG-2. Future Linux kernel updates for the respective releases might address this issue.
CVSS (Common Vulnerability Scoring System) 점수 세부 사항
Info alert:Important note
CVSS scores for open source components depend on vendor-specific factors (e.g. version or build chain). Therefore, Red Hat's score and impact rating can be different from NVD and other vendors. Red Hat remains the authoritative CVE Naming Authority (CNA) source for its products and services (see Red Hat classifications).
CVSS v3 점수 분석
| Red Hat | NVD | cve.org | |
|---|---|---|---|
| 기본 점수 | 5.5 | 5.5 | N/A |
| 공격 벡터 | Local | Local | N/A |
| 공격 복잡성 | Low | Low | N/A |
| 필요한 권한 | Low | Low | N/A |
| 사용자 상호 작용 | None | None | N/A |
| 범위 | Unchanged | Unchanged | N/A |
| 기밀성 | None | None | N/A |
| 무결성에 미치는 영향 | None | None | N/A |
| 가용성에 미치는 영향 | High | High | N/A |
벡터
Red Hat: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
NVD: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CVSS v2 점수 분석
| Red Hat | NVD | cve.org | |
|---|---|---|---|
| 기본 점수 | 4.9 | 4.9 | N/A |
| 공격 벡터 | Local | Local | N/A |
| 액세스 복잡성 | Low | Low | N/A |
| 인증 | None | None | N/A |
| 기밀성에 미치는 영향 | None | None | N/A |
| 무결성에 미치는 영향 | None | None | N/A |
| 가용성에 미치는 영향 | Complete | Complete | N/A |
벡터
Red Hat: AV:L/AC:L/Au:N/C:N/I:N/A:C
NVD: AV:L/AC:L/Au:N/C:N/I:N/A:C
취약점 이해 (CWE)
Availability
Technical Impact: DoS: Crash, Exit, or Restart
NULL pointer dereferences usually result in the failure of the process unless exception handling (on some platforms) is available and implemented. Even when exception handling is being used, it can still be very difficult to return the software to a safe state of operation.
Integrity,Confidentiality
Technical Impact: Execute Unauthorized Code or Commands; Read Memory; Modify Memory
In rare circumstances, when NULL is equivalent to the 0x0 memory address and privileged code can access it, then writing or reading memory is possible, which may lead to code execution.
감사의 말
Red Hat would like to thank Igor Redko (Virtuozzo) and Vasily Averin (Virtuozzo) for reporting this issue.