CVE-2006-0457

Advisory lineage Upstream: 0 Downstream: 1
Downstream
Modified
Published: 14 Mar 2006, 02:00
Last modified:07 Aug 2024, 16:34

Vulnerability Summary

Overall Risk (default)
medium
29/100
CVSS Score
7.1 HIGH
v2.0 (nvd)
EPSS Score
1.5% LOW
2% probability 0.00%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

14 Mar 2006, 02:00
Published
Vulnerability first disclosed
07 Aug 2024, 16:34
Last Modified
Vulnerability information updated

Description

Race condition in the (1) add_key, (2) request_key, and (3) keyctl functions in Linux kernel 2.6.x allows local users to cause a denial of service (crash) or read sensitive kernel memory by modifying the length of a string argument between the time that the kernel calculates the length and when it copies the data into kernel memory.

CVSS Metrics

  • v2.0HIGHScore: 7.1AV:N/AC:H/Au:N/C:C/I:N/A:C

EPSS Trends

Current EPSS score: 1.50% Percentile: 81%

Affected Systems

  • linuxlinux_kernel

    2.6.0 | 2.6.0:test1 | 2.6.0:test10 | 2.6.0:test11 | 2.6.0:test2 | 2.6.0:test3 | 2.6.0:test4 | 2.6.0:test5 | 2.6.0:test6 | 2.6.0:test7 | 2.6.0:test8 | 2.6.0:test9 | 2.6.1 | 2.6.1:rc1 | 2.6.1:rc2 | 2.6.3 | 2.6.4 | 2.6.5 | 2.6.6 | 2.6.6:rc1 | 2.6.7 | 2.6.7:rc1 | 2.6.8 | 2.6.8:rc1 | 2.6.8:rc2 | 2.6.8:rc3 | 2.6.8.1 | 2.6.8.1.5 | 2.6.9:2.6.20 | 2.6.10 | 2.6.10:rc2 | 2.6.11 | 2.6.11:rc1 | 2.6.11:rc2 | 2.6.11:rc3 | 2.6.11:rc4 | 2.6.11.1 | 2.6.11.2 | 2.6.11.3 | 2.6.11.4 | 2.6.11.5 | 2.6.11.6 | 2.6.11.7 | 2.6.11.8 | 2.6.11.9 | 2.6.11.10 | 2.6.11.11 | 2.6.11.12 | 2.6.11_rc1_bk6 | 2.6.12 | 2.6.12:rc1 | 2.6.12:rc4 | 2.6.12:rc5 | 2.6.12.1 | 2.6.12.2 | 2.6.12.3 | 2.6.12.4 | 2.6.12.5 | 2.6.12.6 | 2.6.13 | 2.6.13:rc1 | 2.6.13:rc4 | 2.6.13:rc6 | 2.6.13:rc7 | 2.6.13.1 | 2.6.13.2 | 2.6.13.3 | 2.6.13.4 | 2.6.14 | 2.6.14:rc1 | 2.6.14:rc2 | 2.6.14:rc3 | 2.6.14:rc4 | 2.6.14.1 | 2.6.14.2 | 2.6.14.3 | 2.6.14.4 | 2.6.15 | 2.6.15:rc1 | 2.6.15:rc3 | 2.6.15:rc4 | 2.6.15:rc5 | 2.6.15:rc6 | 2.6.15:rc7 | 2.6.15.1 | 2.6.15.2 | 2.6.15.3 | 2.6.15.4 | 2.6.15.5

References (13)