MEDIUM
security flaw
Published Mar 12, 2006
4.9
MEDIUMCVSS 2.0
EPSS 0.46%
Description
sys_mbind in mempolicy.c in Linux kernel 2.6.16 and earlier does not sanity check the maxnod variable before making certain computations for the get_nodes function, which has unknown impact and attack vectors.
Affected products
No data.
OR
- ≤ 2.6.16
- 2.6.0
- 2.6.1
- 2.6.1
- 2.6.1
- 2.6.1
- 2.6.2
- 2.6.2
- 2.6.2
- 2.6.2
- 2.6.3
- 2.6.3
- 2.6.3
- 2.6.3
- 2.6.3
- 2.6.4
- 2.6.4
- 2.6.4
- 2.6.4
- 2.6.5
- 2.6.5
- 2.6.5
- 2.6.5
- 2.6.6
- 2.6.6
- 2.6.6
- 2.6.6
- 2.6.7
- 2.6.7
- 2.6.7
- 2.6.7
- 2.6.8
- 2.6.8
- 2.6.8
- 2.6.8
- 2.6.8
- 2.6.8.1
- 2.6.9
- 2.6.9
- 2.6.9
- 2.6.9
- 2.6.9
- 2.6.10
- 2.6.10
- 2.6.10
- 2.6.10
- 2.6.11
- 2.6.11
- 2.6.11
- 2.6.11
- 2.6.11
- 2.6.11
- 2.6.11.1
- 2.6.11.2
- 2.6.11.3
- 2.6.11.4
- 2.6.11.5
- 2.6.11.6
- 2.6.11.7
- 2.6.11.8
- 2.6.11.9
- 2.6.11.10
- 2.6.11.11
- 2.6.11.12
- 2.6.12
- 2.6.12
- 2.6.12
- 2.6.12
- 2.6.12
- 2.6.12
- 2.6.12
- 2.6.12.1
- 2.6.12.2
- 2.6.12.3
- 2.6.12.4
- 2.6.12.5
- 2.6.12.6
- 2.6.13
- 2.6.13
- 2.6.13
- 2.6.13
- 2.6.13
- 2.6.13
- 2.6.13
- 2.6.13
- 2.6.13.1
- 2.6.13.2
- 2.6.13.3
- 2.6.13.4
- 2.6.13.5
- 2.6.14
- 2.6.14
- 2.6.14
- 2.6.14
- 2.6.14
- 2.6.14
- 2.6.14.1
- 2.6.14.2
- 2.6.14.3
- 2.6.14.4
- 2.6.14.5
- 2.6.14.6
- 2.6.14.7
- 2.6.15
- 2.6.15
- 2.6.15
- 2.6.15
- 2.6.15
- 2.6.15
- 2.6.15
- 2.6.15
- 2.6.15.1
- 2.6.15.2
- 2.6.15.3
- 2.6.15.4
- 2.6.15.5
- 2.6.15.6
- 2.6.15.7
- 2.6.16
- 2.6.16
- 2.6.16
- 2.6.16
- 2.6.16
- 2.6.16
No data.
Red Hat Enterprise Linux 4
kernel-0:2.6.9-55.EL
Fixed · RHBA-2007:0304
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 4 | kernel-0:2.6.9-55.EL | Fixed | RHBA-2007:0304 |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (0)
No CWE recorded.
References (23)
- http://lkml.org/lkml/2006/2/27/355 x_refsource_CONFIRM
- http://rhn.redhat.com/errata/RHBA-2007-0304.html vendor-advisoryx_refsource_REDHAT
- http://secunia.com/advisories/19955 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/20398 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/20914 third-party-advisoryx_refsource_SECUNIA
- http://securitytracker.com/id?1015752 vdb-entryx_refsource_SECTRACK
- http://www.debian.org/security/2006/dsa-1103 vendor-advisoryx_refsource_DEBIAN
- http://www.kernel.org/git/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=636f13c174dd7c84a437d3c3e8fa66f03f7fda63 x_refsource_CONFIRM
- http://www.kernel.org/git/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commitdiff%3Bh=636f13c174dd7c84a437d3c3e8fa66f03f7fda63 x_refsource_CONFIRM
- http://www.mandriva.com/security/advisories?name=MDKSA-2006:059 vendor-advisoryx_refsource_MANDRIVA
- http://www.novell.com/linux/security/advisories/2006-05-31.html vendor-advisoryx_refsource_SUSE
- http://www.osvdb.org/23895 vdb-entryx_refsource_OSVDB
- http://www.securityfocus.com/bid/16924 vdb-entryx_refsource_BID
- http://www.vupen.com/english/advisories/2006/2554 vdb-entryx_refsource_VUPEN
- https://access.redhat.com/security/cve/CVE-2006-0557 Vendor Advisory
- https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=184510 x_refsource_CONFIRM
- https://bugzilla.redhat.com/show_bug.cgi?id=1618010 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2006-0564 Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/25204 vdb-entryx_refsource_XF
- https://nvd.nist.gov/vuln/detail/CVE-2006-0557
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9674 vdb-entrysignaturex_refsource_OVAL
- https://usn.ubuntu.com/281-1/ vendor-advisoryx_refsource_UBUNTU
- https://www.cve.org/CVERecord?id=CVE-2006-0557
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner sgi
Published Mar 12, 2006
Updated Aug 7, 2024
Reserved Feb 6, 2006
Link CVE-2006-0557
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2006-0564 Assigner sgi
Published Mar 12, 2006
Updated Aug 7, 2024
Exploited since n/a
Link EUVD-2006-0564