CVE-2006-1524
Last modified
CVE-2006-1524 is a vulnerability of currently unknown severity. madvise_remove in Linux kernel 2.6.16 up to 2.6.16.6 does not follow file and mmap restrictions, which allows local users to bypass IPC permissions and replace portions of readonly tmpfs files with zeroes, aka the MADV_REMOVE vulnerability. NOTE: this description was originally written in a way that combined two separate issues. EPSS estimates a 0.43% chance of exploitation in the next 30 days.
Description
madvise_remove in Linux kernel 2.6.16 up to 2.6.16.6 does not follow file and mmap restrictions, which allows local users to bypass IPC permissions and replace portions of readonly tmpfs files with zeroes, aka the MADV_REMOVE vulnerability. NOTE: this description was originally written in a way that combined two separate issues. The mprotect issue now has a separate name, CVE-2006-2071.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux Kernel | 2.6.16 |
| Linux | Linux Kernel | 2.6.16.1 |
| Linux | Linux Kernel | 2.6.16.2 |
| Linux | Linux Kernel | 2.6.16.3 |
| Linux | Linux Kernel | 2.6.16.4 |
| Linux | Linux Kernel | 2.6.16.5 |
| Linux | Linux Kernel | 2.6.16.6 |
References
- http://secunia.com/advisories/19657Patch, Vendor Advisory
- http://secunia.com/advisories/19664Vendor Advisory
- http://secunia.com/advisories/19735Vendor Advisory
- http://secunia.com/advisories/20398Vendor Advisory
- http://secunia.com/advisories/20671Vendor Advisory
- http://secunia.com/advisories/20914Vendor Advisory
- http://www.vupen.com/english/advisories/2006/1391Vendor Advisory
- http://www.vupen.com/english/advisories/2006/1475Vendor Advisory
- http://www.vupen.com/english/advisories/2006/2554Vendor Advisory
- http://secunia.com/advisories/19657Patch, Vendor Advisory
- http://secunia.com/advisories/19664Vendor Advisory
- http://secunia.com/advisories/19735Vendor Advisory
- http://secunia.com/advisories/20398Vendor Advisory
- http://secunia.com/advisories/20671Vendor Advisory
- http://secunia.com/advisories/20914Vendor Advisory
- http://www.vupen.com/english/advisories/2006/1391Vendor Advisory
- http://www.vupen.com/english/advisories/2006/1475Vendor Advisory
- http://www.vupen.com/english/advisories/2006/2554Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2006-1524?
How severe is CVE-2006-1524?
How do I fix CVE-2006-1524?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2006
- CVE-2006-1518Buffer overflow in the open_table function in sql_base.cc in…
- CVE-2006-1519Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultI…
- CVE-2006-1520Format string vulnerability in ANSI C Sender Policy Framewor…
- CVE-2006-1521Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2006-1522The sys_add_key function in the keyring code in Linux kernel…
- CVE-2006-1523The __group_complete_signal function in the RCU signal handl…
- CVE-2006-1525ip_route_input in Linux kernel 2.6 before 2.6.16.8 allows lo…
- CVE-2006-1526Buffer overflow in the X render (Xrender) extension in X.org…
- CVE-2006-1527The SCTP-netfilter code in Linux kernel before 2.6.16.13 all…
- CVE-2006-1528Linux kernel before 2.6.13 allows local users to cause a den…
- CVE-2006-1529Unspecified vulnerability in Firefox and Thunderbird before …
- CVE-2006-1530Unspecified vulnerability in Firefox and Thunderbird before …
Are you affected by CVE-2006-1524?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
