CVE-2006-5751
Vulnerability Summary
Timeline
Description
Integer overflow in the get_fdb_entries function in net/bridge/br_ioctl.c in the Linux kernel before 2.6.18.4 allows local users to execute arbitrary code via a large maxnum value in an ioctl request.
CVSS Metrics
- v2.0•HIGH•Score: 7.2AV:L/AC:L/Au:N/C:C/I:C/A:C
EPSS Trends
Current EPSS score: 0.10%• Percentile: 27%
Affected Systems
- linux•linux_kernel
2.6.0 | 2.6.1 | 2.6.1:rc1 | 2.6.1:rc2 | 2.6.1:rc3 | 2.6.2 | 2.6.2:rc1 | 2.6.2:rc2 | 2.6.2:rc3 | 2.6.3 | 2.6.3:rc1 | 2.6.3:rc2 | 2.6.3:rc3 | 2.6.3:rc4 | 2.6.4 | 2.6.4:rc1 | 2.6.4:rc2 | 2.6.4:rc3 | 2.6.5 | 2.6.5:rc1 | 2.6.5:rc2 | 2.6.5:rc3 | 2.6.6 | 2.6.6:rc1 | 2.6.6:rc2 | 2.6.6:rc3 | 2.6.7 | 2.6.7:rc1 | 2.6.7:rc2 | 2.6.7:rc3 | 2.6.8 | 2.6.8:rc1 | 2.6.8:rc2 | 2.6.8:rc3 | 2.6.8:rc4 | 2.6.8.1 | 2.6.8.1.5 | 2.6.9 | 2.6.9:2.6.20 | 2.6.9:rc1 | 2.6.9:rc2 | 2.6.9:rc3 | 2.6.9:rc4 | 2.6.10 | 2.6.10:rc1 | 2.6.10:rc2 | 2.6.10:rc3 | 2.6.11 | 2.6.11:rc1 | 2.6.11:rc2 | 2.6.11:rc3 | 2.6.11:rc4 | 2.6.11:rc5 | 2.6.11.1 | 2.6.11.2 | 2.6.11.3 | 2.6.11.4 | 2.6.11.5 | 2.6.11.6 | 2.6.11.7 | 2.6.11.8 | 2.6.11.9 | 2.6.11.10 | 2.6.11.11 | 2.6.11.12 | 2.6.11_rc1_bk6 | 2.6.12 | 2.6.12:rc1 | 2.6.12:rc2 | 2.6.12:rc3 | 2.6.12:rc4 | 2.6.12:rc5 | 2.6.12:rc6 | 2.6.12.1 | 2.6.12.2 | 2.6.12.3 | 2.6.12.4 | 2.6.12.5 | 2.6.12.6 | 2.6.13 | 2.6.13:rc1 | 2.6.13:rc2 | 2.6.13:rc3 | 2.6.13:rc4 | 2.6.13:rc5 | 2.6.13:rc6 | 2.6.13:rc7 | 2.6.13.1 | 2.6.13.2 | 2.6.13.3 | 2.6.13.4 | 2.6.14 | 2.6.14:rc1 | 2.6.14:rc2 | 2.6.14:rc3 | 2.6.14:rc4 | 2.6.14:rc5 | 2.6.14.1 | 2.6.14.2 | 2.6.14.3 | 2.6.14.4 | 2.6.14.5 | 2.6.14.6 | 2.6.14.7 | 2.6.15 | 2.6.15:rc1 | 2.6.15:rc3 | 2.6.15:rc4 | 2.6.15:rc5 | 2.6.15:rc6 | 2.6.15:rc7 | 2.6.15.1 | 2.6.15.2 | 2.6.15.3 | 2.6.15.4 | 2.6.15.5 | 2.6.15.6 | 2.6.15.7 | 2.6.16 | 2.6.16:rc1 | 2.6.16:rc2 | 2.6.16:rc3 | 2.6.16:rc4 | 2.6.16:rc5 | 2.6.16:rc6 | 2.6.16.1 | 2.6.16.2 | 2.6.16.3 | 2.6.16.4 | 2.6.16.5 | 2.6.16.6 | 2.6.16.7 | 2.6.16.8 | 2.6.16.9 | 2.6.16.10 | 2.6.16.11 | 2.6.16.12 | 2.6.16.13 | 2.6.16.14 | 2.6.16.15 | 2.6.16.16 | 2.6.16.17 | 2.6.16.18 | 2.6.16.19 | 2.6.16.20 | 2.6.16.21 | 2.6.16.22 | 2.6.16.23 | 2.6.16.24 | 2.6.16.25 | 2.6.16.26 | 2.6.16.27 | 2.6.16.28 | 2.6.16.29 | 2.6.16.30 | 2.6.16.31 | 2.6.16.32 | 2.6.16.33 | 2.6.17 | 2.6.17:rc1 | 2.6.17:rc2 | 2.6.17:rc3 | 2.6.17:rc4 | 2.6.17:rc5 | 2.6.17:rc6 | 2.6.17.1 | 2.6.17.2 | 2.6.17.3 | 2.6.17.4 | 2.6.17.5 | 2.6.17.6 | 2.6.17.7 | 2.6.17.8 | 2.6.17.9 | 2.6.17.10 | 2.6.17.11 | 2.6.17.12 | 2.6.17.13 | 2.6.17.14 | 2.6.18 | 2.6.18:rc1 | 2.6.18:rc2 | 2.6.18:rc3 | 2.6.18:rc4 | 2.6.18:rc5 | 2.6.18:rc6 | 2.6.18:rc7 | 2.6.18.1 | 2.6.18.2 | 2.6.18.3
References (29)
- http://www.kernel.org/git/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=ba8379b220509e9448c00a77cf6c15ac2a559cc7
- http://www.novell.com/linux/security/advisories/2006_79_kernel.html
- http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.18.4
- https://issues.rpath.com/browse/RPL-803
- http://secunia.com/advisories/23073
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10151
- http://www.vupen.com/english/advisories/2006/4781
- http://rhn.redhat.com/errata/RHSA-2007-0014.html
- http://www.mandriva.com/security/advisories?name=MDKSA-2007:012
- http://secunia.com/advisories/23593
- http://www.novell.com/linux/security/advisories/2007_21_kernel.html
- https://issues.rpath.com/browse/RPL-837
- http://support.avaya.com/elmodocs2/security/ASA-2007-063.htm
- http://secunia.com/advisories/23384
- http://secunia.com/advisories/23752
- http://secunia.com/advisories/24206
- http://www.kernel.org/git/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=blobdiff%3Bh=4c61a7e0a86e1ae9e16867f9f8e4b0412b8edbaf%3Bhp=4e4119a1213925568b8a1acdef9bf52b98b19da3%3Bhb=ba8379b220509e9448c00a77cf6c15ac2a559cc7%3Bf=net/bridge/br_ioctl.c
- http://secunia.com/advisories/23252
- http://secunia.com/advisories/23474
- http://projects.info-pull.com/mokb/MOKB-29-11-2006.html
- http://www.us.debian.org/security/2006/dsa-1233
- http://secunia.com/advisories/23370
- http://secunia.com/advisories/23997
- http://www.securityfocus.com/bid/21353
- http://secunia.com/advisories/24547
- http://www.mandriva.com/security/advisories?name=MDKSA-2007:002
- http://www.ubuntu.com/usn/usn-395-1
- http://www.securityfocus.com/archive/1/453681/100/0/threaded
- https://exchange.xforce.ibmcloud.com/vulnerabilities/30588