Lucene search

K
redhatcveRedhat.comRH:CVE-2016-9604
HistoryApr 28, 2017 - 11:18 a.m.

CVE-2016-9604

2017-04-2811:18:12
redhat.com
access.redhat.com
11

0.001 Low

EPSS

Percentile

26.4%

It was discovered that root can gain direct access to an internal keyring, such as ‘.dns_resolver’ in RHEL-7 or ‘.builtin_trusted_keys’ upstream, by joining it as its session keyring. This allows root to bypass module signature verification by adding a new public key of its own devising to the keyring.