LOW
madvise_remove in Linux kernel 2.6.16 up to 2.6.16.6 does not follow file and mmap restrictions, which allows local users to bypass IPC permissions and replace portions of readonly tmpfs files with zeroes, aka the MADV_REMOVE vulnerability
Published Apr 19, 2006
3.6
LOWCVSS 2.0
EPSS 0.43%
Description
madvise_remove in Linux kernel 2.6.16 up to 2.6.16.6 does not follow file and mmap restrictions, which allows local users to bypass IPC permissions and replace portions of readonly tmpfs files with zeroes, aka the MADV_REMOVE vulnerability. NOTE: this description was originally written in a way that combined two separate issues. The mprotect issue now has a separate name, CVE-2006-2071.
Affected products
No data.
OR
- 2.6.16
- 2.6.16.1
- 2.6.16.2
- 2.6.16.3
- 2.6.16.4
- 2.6.16.5
- 2.6.16.6
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (17)
- http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.16.6 x_refsource_CONFIRM
- http://lwn.net/Alerts/180820/ vendor-advisoryx_refsource_FEDORA
- http://secunia.com/advisories/19657 third-party-advisoryx_refsource_SECUNIAPatchVendor Advisory
- http://secunia.com/advisories/19664 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/19735 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/20398 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/20671 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/20914 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://www.debian.org/security/2006/dsa-1097 vendor-advisoryx_refsource_DEBIAN
- http://www.debian.org/security/2006/dsa-1103 vendor-advisoryx_refsource_DEBIAN
- http://www.novell.com/linux/security/advisories/2006-05-31.html vendor-advisoryx_refsource_SUSE
- http://www.osvdb.org/24714 vdb-entryx_refsource_OSVDB
- http://www.securityfocus.com/bid/17587 vdb-entryx_refsource_BIDPatch
- http://www.vupen.com/english/advisories/2006/1391 vdb-entryx_refsource_VUPENVendor Advisory
- http://www.vupen.com/english/advisories/2006/1475 vdb-entryx_refsource_VUPENVendor Advisory
- http://www.vupen.com/english/advisories/2006/2554 vdb-entryx_refsource_VUPENVendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/25870 vdb-entryx_refsource_XF
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Apr 19, 2006
Updated Aug 7, 2024
Reserved Mar 30, 2006
Link CVE-2006-1524
CISA Vulnrichment
Updated n/a