security flaw
Published Apr 20, 2006
2.1
LOWCVSS 2.0
EPSS 0.45%
Description
The Linux kernel before 2.6.16.9 and the FreeBSD kernel, when running on AMD64 and other 7th and 8th generation AuthenticAMD processors, only save/restore the FOP, FIP, and FDP x87 registers in FXSAVE/FXRSTOR when an exception is pending, which allows one process to determine portions of the state of floating point instructions of other processes, which can be leveraged to obtain sensitive information such as cryptographic keys. NOTE: this is the documented behavior of AMD64 processors, but it is inconsistent with Intel processors in a security-relevant fashion that was not addressed by the kernels.
Affected products
No data.
- n/a
- ≤ 2.6.16.8
- 2.6.0
- 2.6.0
- 2.6.0
- 2.6.0
- 2.6.0
- 2.6.0
- 2.6.0
- 2.6.0
- 2.6.0
- 2.6.0
- 2.6.0
- 2.6.0
- 2.6.1
- 2.6.1
- 2.6.1
- 2.6.1
- 2.6.2
- 2.6.2
- 2.6.2
- 2.6.2
- 2.6.3
- 2.6.3
- 2.6.3
- 2.6.3
- 2.6.3
- 2.6.4
- 2.6.4
- 2.6.4
- 2.6.4
- 2.6.5
- 2.6.5
- 2.6.5
- 2.6.5
- 2.6.6
- 2.6.6
- 2.6.6
- 2.6.6
- 2.6.7
- 2.6.7
- 2.6.7
- 2.6.7
- 2.6.8
- 2.6.8
- 2.6.8
- 2.6.8
- 2.6.8
- 2.6.9
- 2.6.9
- 2.6.9
- 2.6.9
- 2.6.9
- 2.6.9
- 2.6.10
- 2.6.10
- 2.6.10
- 2.6.10
- 2.6.11
- 2.6.11
- 2.6.11
- 2.6.11
- 2.6.11
- 2.6.11
- 2.6.11.1
- 2.6.11.2
- 2.6.11.3
- 2.6.11.4
- 2.6.11.5
- 2.6.11.6
- 2.6.11.7
- 2.6.11.8
- 2.6.11.9
- 2.6.11.10
- 2.6.11.11
- 2.6.11.12
- 2.6.12
- 2.6.12
- 2.6.12
- 2.6.12
- 2.6.12
- 2.6.12
- 2.6.12.1
- 2.6.12.2
- 2.6.12.3
- 2.6.12.4
- 2.6.12.5
- 2.6.12.6
- 2.6.13
- 2.6.13
- 2.6.13
- 2.6.13
- 2.6.13
- 2.6.13
- 2.6.13
- 2.6.13
- 2.6.13.1
- 2.6.13.2
- 2.6.13.3
- 2.6.13.4
- 2.6.14
- 2.6.14
- 2.6.14
- 2.6.14
- 2.6.14
- 2.6.14
- 2.6.14.1
- 2.6.14.2
- 2.6.14.3
- 2.6.14.4
- 2.6.14.5
- 2.6.14.6
- 2.6.14.7
- 2.6.15
- 2.6.15
- 2.6.15
- 2.6.15
- 2.6.15
- 2.6.15
- 2.6.15
- 2.6.15.1
- 2.6.15.2
- 2.6.15.3
- 2.6.15.4
- 2.6.15.5
- 2.6.15.6
- 2.6.15.7
- 2.6.16
- 2.6.16
- 2.6.16
- 2.6.16
- 2.6.16
- 2.6.16
- 2.6.16
- 2.6.16.1
- 2.6.16.2
- 2.6.16.3
- 2.6.16.4
- 2.6.16.5
- 2.6.16.6
- 2.6.16.7
- 2.6.16_rc7
- 2.6_test9_cvs
No data.
Red Hat Enterprise Linux 3
kernel-0:2.4.21-47.EL
Fixed · RHSA-2006:0437
Red Hat Enterprise Linux 4
kernel-0:2.6.9-42.EL
Fixed · RHSA-2006:0575
Red Hat Enterprise Linux AS (Advanced Server) version 2.1
n/a
Fixed · RHSA-2006:0579
Red Hat Enterprise Linux ES version 2.1
n/a
Fixed · RHSA-2006:0579
Red Hat Enterprise Linux WS version 2.1
n/a
Fixed · RHSA-2006:0579
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 3 | kernel-0:2.4.21-47.EL | Fixed | RHSA-2006:0437 |
| Red Hat Enterprise Linux 4 | kernel-0:2.6.9-42.EL | Fixed | RHSA-2006:0575 |
| Red Hat Enterprise Linux AS (Advanced Server) version 2.1 | n/a | Fixed | RHSA-2006:0579 |
| Red Hat Enterprise Linux ES version 2.1 | n/a | Fixed | RHSA-2006:0579 |
| Red Hat Enterprise Linux WS version 2.1 | n/a | Fixed | RHSA-2006:0579 |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
No CVSS v3.0 score for this CVE.
AV:L/AC:L/Au:N/C:P/I:N/A:N
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (10 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 0.45% (0.00448) | 36.64th | v5 (v2026.06.15) |
| Jun 15, 2026 | 0.45% (0.00448) | 35.45th | v5 (v2026.06.15) |
| Mar 17, 2025 | 0.08% (0.00078) | 20.91th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.10% (0.00101) | 43.16th | v3 (v2023.03.01) |
| Jun 16, 2023 | 0.10% (0.00104) | 41.44th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.07% (0.00073) | 29.72th | v3 (v2023.03.01) |
| Mar 6, 2023 | 1.55% (0.01547) | 74.98th | v2 (v2022.01.01) |
| Feb 23, 2023 | 1.55% (0.01547) | 74.94th | v2 (v2022.01.01) |
| Apr 1, 2022 | 1.55% (0.01547) | 72.92th | v2 (v2022.01.01) |
| Feb 4, 2022 | 1.55% (0.01547) | 51.82th | v2 (v2022.01.01) |
References (54)
- ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-06:14.fpu.asc vendor-advisoryx_refsource_FREEBSD
- http://kb.vmware.com/kb/2533126 x_refsource_CONFIRM
- http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.16.9 x_refsource_CONFIRM
- http://lists.opensuse.org/opensuse-security-announce/2014-03/msg00021.html vendor-advisoryx_refsource_SUSE
- http://lwn.net/Alerts/180820/ vendor-advisoryx_refsource_FEDORA
- http://marc.info/?l=linux-kernel&m=114548768214478&w=2 mailing-listx_refsource_MLIST
- http://secunia.com/advisories/19715 third-party-advisoryx_refsource_SECUNIAPatchVendor Advisory
- http://secunia.com/advisories/19724 third-party-advisoryx_refsource_SECUNIAPatchVendor Advisory
- http://secunia.com/advisories/19735 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/20398 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/20671 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/20716 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/20914 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/21035 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/21136 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/21465 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/21983 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/22417 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/22875 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/22876 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://security.freebsd.org/advisories/FreeBSD-SA-06:14-amd.txt x_refsource_MISC
- http://securitytracker.com/id?1015966 vdb-entryx_refsource_SECTRACK
- http://support.avaya.com/elmodocs2/security/ASA-2006-180.htm x_refsource_CONFIRM
- http://support.avaya.com/elmodocs2/security/ASA-2006-200.htm x_refsource_CONFIRM
- http://www.debian.org/security/2006/dsa-1097 vendor-advisoryx_refsource_DEBIAN
- http://www.debian.org/security/2006/dsa-1103 vendor-advisoryx_refsource_DEBIAN
- http://www.novell.com/linux/security/advisories/2006-05-31.html vendor-advisoryx_refsource_SUSE
- http://www.osvdb.org/24746 vdb-entryx_refsource_OSVDB
- http://www.osvdb.org/24807 vdb-entryx_refsource_OSVDB
- http://www.redhat.com/support/errata/RHSA-2006-0437.html vendor-advisoryx_refsource_REDHAT
- http://www.redhat.com/support/errata/RHSA-2006-0575.html vendor-advisoryx_refsource_REDHAT
- http://www.redhat.com/support/errata/RHSA-2006-0579.html vendor-advisoryx_refsource_REDHAT
- http://www.securityfocus.com/archive/1/431341 mailing-listx_refsource_BUGTRAQ
- http://www.securityfocus.com/archive/1/451404/100/0/threaded mailing-listx_refsource_BUGTRAQ
- http://www.securityfocus.com/archive/1/451417/100/200/threaded mailing-listx_refsource_BUGTRAQ
- http://www.securityfocus.com/archive/1/451419/100/200/threaded mailing-listx_refsource_BUGTRAQ
- http://www.securityfocus.com/archive/1/451421/100/0/threaded mailing-listx_refsource_BUGTRAQ
- http://www.securityfocus.com/bid/17600 vdb-entryx_refsource_BIDPatch
- http://www.ubuntu.com/usn/usn-302-1 vendor-advisoryx_refsource_UBUNTU
- http://www.vmware.com/download/esx/esx-213-200610-patch.html x_refsource_CONFIRM
- http://www.vmware.com/download/esx/esx-254-200610-patch.html x_refsource_CONFIRM
- http://www.vupen.com/english/advisories/2006/1426 vdb-entryx_refsource_VUPENVendor Advisory
- http://www.vupen.com/english/advisories/2006/1475 vdb-entryx_refsource_VUPENVendor Advisory
- http://www.vupen.com/english/advisories/2006/2554 vdb-entryx_refsource_VUPENVendor Advisory
- http://www.vupen.com/english/advisories/2006/4353 vdb-entryx_refsource_VUPENVendor Advisory
- http://www.vupen.com/english/advisories/2006/4502 vdb-entryx_refsource_VUPENVendor Advisory
- https://access.redhat.com/security/cve/CVE-2006-1056 Vendor Advisory
- https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=187910 x_refsource_CONFIRM
- https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=187911 x_refsource_CONFIRM
- https://bugzilla.redhat.com/show_bug.cgi?id=1618025 Issue Tracking
- https://exchange.xforce.ibmcloud.com/vulnerabilities/25871 vdb-entryx_refsource_XF
- https://nvd.nist.gov/vuln/detail/CVE-2006-1056
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9995 vdb-entrysignaturex_refsource_OVAL
- https://www.cve.org/CVERecord?id=CVE-2006-1056
Change history (0)
No recorded changes yet.