CVE-2016-0728: Canonical Ubuntu Linux

High severity, CVSS 7.8. EPSS: 3.4% chance of exploitation in the next 30 days.

The join_session_keyring function in security/keys/process_keys.c in the Linux kernel before 4.4.1 mishandles object references in a certain error case, which allows local users to gain privileges or cause a denial of service (integer overflow and use-after-free) via crafted keyctl commands.

Affected products

  • Canonical Ubuntu Linux: version 12.04 only; version 14.04 only; version 15.04 only; version 15.10 only
  • Debian Debian Linux: version 8.0 only
  • Google Android: version 4.0 only; version 4.0.1 only; version 4.0.2 only; version 4.0.3 only; version 4.0.4 only; version 4.1 only; …
  • HP Server Migration Pack: up to and including 7.5
  • Linux Linux Kernel: from 3.8, before 3.10.95 (fixed in 3.10.95); from 3.11, before 3.12.53 (fixed in 3.12.53); from 3.13, before 3.14.59 (fixed in 3.14.59); from 3.15, before 3.16.35 (fixed in 3.16.35); from 3.17, before 3.18.26 (fixed in 3.18.26); from 3.19, before 4.1.16 (fixed in 4.1.16); …

Published 2016-02-08. Last modified 2026-06-17.