CVE-2015-8539: Canonical Ubuntu Linux

High severity, CVSS 7.8. EPSS: 0.4% chance of exploitation in the next 30 days.

The KEYS subsystem in the Linux kernel before 4.4 allows local users to gain privileges or cause a denial of service (BUG) via crafted keyctl commands that negatively instantiate a key, related to security/keys/encrypted-keys/encrypted.c, security/keys/trusted.c, and security/keys/user_defined.c.

Affected products

  • Canonical Ubuntu Linux: version 12.04 only; version 14.04 only
  • Linux Linux Kernel: before 4.4 (fixed in 4.4); version 4.4 only
  • Suse Linux Enterprise Real Time Extension: version 12 only

Published 2016-02-08. Last modified 2026-06-17.