The KEYS subsystem in the Linux kernel before 4.10.13 allows local users to cause a denial of service (memory consumption) via a series of KEYREQKEYDEFLTHREADKEYRING keyctlsetreqkey_keyring calls.
{ "urgency": "not yet assigned" }