SB20251230270 - Input validation error in Linux kernel keys
Published: December 30, 2025 Updated: December 30, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Input validation error (CVE-ID: CVE-2023-54170)
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to improper input validation within the construct_alloc_key() function in security/keys/request_key.c. A local user can perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/00edfa6d4fe022942e2f2e6f3294ff13ef78b15c
- https://git.kernel.org/stable/c/0a6b0ca58685be34979236f83f2b322635b80b32
- https://git.kernel.org/stable/c/65bd66a794bfa059375ec834885bb610d75c0182
- https://git.kernel.org/stable/c/9aecfebea24fe6071ace5cc9fd6d690b87276bbb
- https://git.kernel.org/stable/c/d55901522f96082a43b9842d34867363c0cdbac5
- https://git.kernel.org/stable/c/e091bb55af9a930801f83df78195a908a76e1479
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.4.7