CVE-2006-0744
Last modified
CVE-2006-0744 is a vulnerability of currently unknown severity. Linux kernel before 2.6.16.5 does not properly handle uncanonical return addresses on Intel EM64T CPUs, which reports an exception in the SYSRET instead of the next instruction, which causes the kernel exception handler to run on the user stack with the wrong GS.. EPSS estimates a 0.46% chance of exploitation in the next 30 days.
Description
Linux kernel before 2.6.16.5 does not properly handle uncanonical return addresses on Intel EM64T CPUs, which reports an exception in the SYSRET instead of the next instruction, which causes the kernel exception handler to run on the user stack with the wrong GS.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Linux | Linux Kernel | 2.6.0 | — |
| Linux | Linux Kernel | 2.6.1 | — |
| Linux | Linux Kernel | 2.6.2 | — |
| Linux | Linux Kernel | 2.6.3 | — |
| Linux | Linux Kernel | 2.6.4 | — |
| Linux | Linux Kernel | 2.6.5 | — |
| Linux | Linux Kernel | 2.6.6 | — |
| Linux | Linux Kernel | 2.6.7 | — |
| Linux | Linux Kernel | 2.6.8 | — |
| Linux | Linux Kernel | 2.6.9 | — |
| Linux | Linux Kernel | 2.6.10 | — |
| Linux | Linux Kernel | 2.6.11 | — |
| Linux | Linux Kernel | 2.6.11.1 | — |
| Linux | Linux Kernel | 2.6.11.2 | — |
| Linux | Linux Kernel | 2.6.11.3 | — |
| Linux | Linux Kernel | 2.6.11.4 | — |
| Linux | Linux Kernel | 2.6.11.5 | — |
| Linux | Linux Kernel | 2.6.11.6 | — |
| Linux | Linux Kernel | 2.6.11.7 | — |
| Linux | Linux Kernel | 2.6.11.8 | — |
| Linux | Linux Kernel | 2.6.11.9 | — |
| Linux | Linux Kernel | 2.6.11.10 | — |
| Linux | Linux Kernel | 2.6.11.11 | — |
| Linux | Linux Kernel | 2.6.11.12 | — |
| Linux | Linux Kernel | 2.6.12 | Rc1 |
| Linux | Linux Kernel | 2.6.12.1 | — |
| Linux | Linux Kernel | 2.6.12.2 | — |
| Linux | Linux Kernel | 2.6.12.3 | — |
| Linux | Linux Kernel | 2.6.12.4 | — |
| Linux | Linux Kernel | 2.6.12.5 | — |
| Linux | Linux Kernel | 2.6.12.6 | — |
| Linux | Linux Kernel | 2.6.13 | — |
| Linux | Linux Kernel | 2.6.13.1 | — |
| Linux | Linux Kernel | 2.6.13.2 | — |
| Linux | Linux Kernel | 2.6.13.3 | — |
| Linux | Linux Kernel | 2.6.13.4 | — |
| Linux | Linux Kernel | 2.6.14 | — |
| Linux | Linux Kernel | 2.6.14.1 | — |
| Linux | Linux Kernel | 2.6.14.2 | — |
| Linux | Linux Kernel | 2.6.14.3 | — |
| Linux | Linux Kernel | 2.6.14.4 | — |
| Linux | Linux Kernel | 2.6.14.5 | — |
| Linux | Linux Kernel | 2.6.14.6 | — |
| Linux | Linux Kernel | 2.6.14.7 | — |
| Linux | Linux Kernel | 2.6.15 | — |
| Linux | Linux Kernel | 2.6.15.1 | — |
| Linux | Linux Kernel | 2.6.15.2 | — |
| Linux | Linux Kernel | 2.6.15.3 | — |
| Linux | Linux Kernel | 2.6.15.4 | — |
| Linux | Linux Kernel | 2.6.15.5 | — |
Showing 50 of 59 affected configurations. See NVD for the full list.
References
- http://secunia.com/advisories/19639Vendor Advisory
- http://secunia.com/advisories/19735Vendor Advisory
- http://secunia.com/advisories/20157Vendor Advisory
- http://secunia.com/advisories/20237Vendor Advisory
- http://secunia.com/advisories/20716Vendor Advisory
- http://secunia.com/advisories/20914Vendor Advisory
- http://secunia.com/advisories/21136Vendor Advisory
- http://secunia.com/advisories/21179Vendor Advisory
- http://secunia.com/advisories/21498Vendor Advisory
- http://secunia.com/advisories/21745Vendor Advisory
- http://secunia.com/advisories/21983Vendor Advisory
- http://secunia.com/advisories/19639Vendor Advisory
- http://secunia.com/advisories/19735Vendor Advisory
- http://secunia.com/advisories/20157Vendor Advisory
- http://secunia.com/advisories/20237Vendor Advisory
- http://secunia.com/advisories/20716Vendor Advisory
- http://secunia.com/advisories/20914Vendor Advisory
- http://secunia.com/advisories/21136Vendor Advisory
- http://secunia.com/advisories/21179Vendor Advisory
- http://secunia.com/advisories/21498Vendor Advisory
- http://secunia.com/advisories/21745Vendor Advisory
- http://secunia.com/advisories/21983Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2006-0744?
How severe is CVE-2006-0744?
How do I fix CVE-2006-0744?
Are you affected by CVE-2006-0744?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
