Linux Kernel join_session_keyring Reference Counting Privilege Escalation Exploit

The join_session_keyring() function in security/keys/process_keys.c in the Linux kernel is prone to a reference counter overflow that occurs when a process repeatedly tries to join an already existing keyring. This vulnerability can be leveraged by local unprivileged attackers to gain root privileges on the affected systems.
Friday, March 4, 2016 - 00:00