VDB
CVE-2006-1524
CVE-2006-1524
PUBLISHED
CVSS 3.5999999046325684 LOW
madvise_remove in Linux kernel 2.6.16 up to 2.6.16.6 does not follow file and mmap restrictions, which allows local users to bypass IPC permissions and replace portions of readonly tmpfs files with zeroes, aka the MADV_REMOVE vulnerability. NOTE: this description was originally written in a way that combined two separate issues. The mprotect issue now has a separate name, CVE-2006-2071.
EPSS 0.43% · 35.6th percentile
Risk Scores
CVSS 2.0
3.5999999046325684
EPSS Score
0.43%
35.6th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | n/a | n/a |
| linux | linux_kernel | 2.6.16.1, 2.6.16.2, 2.6.16.3 |
Timeline
- Apr 19, 2006 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 21, 2022 EPSS Score
- Jul 13, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 27, 2022 EPSS Score
- Dec 19, 2022 EPSS Score
- Feb 10, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 4, 2023 EPSS Score
- May 27, 2023 EPSS Score
References
- 20398 third-party-advisory
- http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.16.6 url
- 19657 third-party-advisory
- 19735 third-party-advisory
- FEDORA-2006-423 vendor-advisory
- 20914 third-party-advisory
- http://secunia.com/advisories/19664 advisory
- http://www.debian.org/security/2006/dsa-1097 technical
- http://www.vupen.com/english/advisories/2006/1475 advisory
- http://www.debian.org/security/2006/dsa-1103 technical
- http://www.vupen.com/english/advisories/2006/1391 advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/25870 technical
- https://nvd.nist.gov/vuln/detail/CVE-2006-1524 advisory
- http://lwn.net/Alerts/180820 url
- http://secunia.com/advisories/20671 url
- http://www.novell.com/linux/security/advisories/2006-05-31.html url
- http://www.osvdb.org/24714 url
- http://www.securityfocus.com/bid/17587 url
- http://www.vupen.com/english/advisories/2006/2554 url