CVE-2006-1524
Last modified
CVE-2006-1524 is a vulnerability of currently unknown severity. madvise_remove in Linux kernel 2.6.16 up to 2.6.16.6 does not follow file and mmap restrictions, which allows local users to bypass IPC permissions and replace portions of readonly tmpfs files with zeroes, aka the MADV_REMOVE vulnerability. NOTE: this description was originally written in a way that combined two separate issues. EPSS estimates a 0.43% chance of exploitation in the next 30 days.
Description
madvise_remove in Linux kernel 2.6.16 up to 2.6.16.6 does not follow file and mmap restrictions, which allows local users to bypass IPC permissions and replace portions of readonly tmpfs files with zeroes, aka the MADV_REMOVE vulnerability. NOTE: this description was originally written in a way that combined two separate issues. The mprotect issue now has a separate name, CVE-2006-2071.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux Kernel | 2.6.16 |
| Linux | Linux Kernel | 2.6.16.1 |
| Linux | Linux Kernel | 2.6.16.2 |
| Linux | Linux Kernel | 2.6.16.3 |
| Linux | Linux Kernel | 2.6.16.4 |
| Linux | Linux Kernel | 2.6.16.5 |
| Linux | Linux Kernel | 2.6.16.6 |
References
- http://secunia.com/advisories/19657Patch, Vendor Advisory
- http://secunia.com/advisories/19664Vendor Advisory
- http://secunia.com/advisories/19735Vendor Advisory
- http://secunia.com/advisories/20398Vendor Advisory
- http://secunia.com/advisories/20671Vendor Advisory
- http://secunia.com/advisories/20914Vendor Advisory
- http://www.vupen.com/english/advisories/2006/1391Vendor Advisory
- http://www.vupen.com/english/advisories/2006/1475Vendor Advisory
- http://www.vupen.com/english/advisories/2006/2554Vendor Advisory
- http://secunia.com/advisories/19657Patch, Vendor Advisory
- http://secunia.com/advisories/19664Vendor Advisory
- http://secunia.com/advisories/19735Vendor Advisory
- http://secunia.com/advisories/20398Vendor Advisory
- http://secunia.com/advisories/20671Vendor Advisory
- http://secunia.com/advisories/20914Vendor Advisory
- http://www.vupen.com/english/advisories/2006/1391Vendor Advisory
- http://www.vupen.com/english/advisories/2006/1475Vendor Advisory
- http://www.vupen.com/english/advisories/2006/2554Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2006-1524?
How severe is CVE-2006-1524?
How do I fix CVE-2006-1524?
Are you affected by CVE-2006-1524?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
