CVE-2015-8539: Canonical Ubuntu Linux
High severity, CVSS 7.8. EPSS: 0.4% chance of exploitation in the next 30 days.
The KEYS subsystem in the Linux kernel before 4.4 allows local users to gain privileges or cause a denial of service (BUG) via crafted keyctl commands that negatively instantiate a key, related to security/keys/encrypted-keys/encrypted.c, security/keys/trusted.c, and security/keys/user_defined.c.
Affected products
- Canonical Ubuntu Linux: version 12.04 only; version 14.04 only
- Linux Linux Kernel: before 4.4 (fixed in 4.4); version 4.4 only
- Suse Linux Enterprise Real Time Extension: version 12 only
Published 2016-02-08. Last modified 2026-06-17.