CVE-2007-0006
Advisory lineage Upstream: 0 Downstream: 2
Downstream
Modified
Published: 06 Feb 2007, 19:00
Last modified:07 Aug 2024, 12:03
Vulnerability Summary
Overall Risk (default)
minimal
8/100 CVSS Score
1.9 LOW
v2.0 (nvd)
EPSS Score
0.09% LOW
0% probability 0.00%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected
Timeline
06 Feb 2007, 19:00
Published
Vulnerability first disclosed
07 Aug 2024, 12:03
Last Modified
Vulnerability information updated
Description
The key serial number collision avoidance code in the key_alloc_serial function in Linux kernel 2.6.9 up to 2.6.20 allows local users to cause a denial of service (crash) via vectors that trigger a null dereference, as originally reported as "spinlock CPU recursion."
CVSS Metrics
- v2.0•LOW•Score: 1.9AV:L/AC:M/Au:N/C:N/I:N/A:P
EPSS Trends
Current EPSS score: 0.09%• Percentile: 25%
Affected Systems
- linux•linux_kernel
≤ 2.6.20 | 2.6.9:2.6.20
References (20)
- http://www.redhat.com/support/errata/RHSA-2007-0099.html
- http://secunia.com/advisories/24429
- https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=227495
- http://bugzilla.kernel.org/show_bug.cgi?id=7727
- http://secunia.com/advisories/24259
- http://www.ubuntu.com/usn/usn-451-1
- http://www.mandriva.com/security/advisories?name=MDKSA-2007:047
- http://www.novell.com/linux/security/advisories/2007_21_kernel.html
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9829
- http://secunia.com/advisories/24300
- http://www.securityfocus.com/archive/1/471457
- http://secunia.com/advisories/24482
- http://www.redhat.com/support/errata/RHSA-2007-0085.html
- http://secunia.com/advisories/24752
- http://secunia.com/advisories/24547
- http://secunia.com/advisories/24109
- https://issues.rpath.com/browse/RPL-1097
- http://www.securityfocus.com/bid/22539
- http://secunia.com/advisories/25691
- http://www.mandriva.com/security/advisories?name=MDKSA-2007:060