security flaw
Published Jul 15, 2006
6.2
MEDIUMCVSS 2.0
EPSS 2.20%
Description
Race condition in Linux kernel 2.6.17.4 and earlier allows local users to gain root privileges by using prctl with PR_SET_DUMPABLE in a way that causes /proc/self/environ to become setuid root.
Affected products
No data.
- 2.6.16
- 2.6.16
- 2.6.16
- 2.6.16
- 2.6.16
- 2.6.16
- 2.6.16
- 2.6.16.1
- 2.6.16.2
- 2.6.16.3
- 2.6.16.4
- 2.6.16.5
- 2.6.16.6
- 2.6.16.7
- 2.6.16.8
- 2.6.16.9
- 2.6.16.10
- 2.6.16.11
- 2.6.16.12
- 2.6.16.13
- 2.6.16.14
- 2.6.16.15
- 2.6.16.16
- 2.6.16.17
- 2.6.16.18
- 2.6.16.19
- 2.6.16.20
- 2.6.16.21
- 2.6.16.22
- 2.6.16.23
- 2.6.16.24
- 2.6.17
- 2.6.17
- 2.6.17
- 2.6.17
- 2.6.17
- 2.6.17
- 2.6.17
- 2.6.17.1
- 2.6.17.2
- 2.6.17.3
- 2.6.17.4
No data.
Red Hat Enterprise Linux 4
kernel-0:2.6.9-42.0.2.EL
Fixed · RHSA-2006:0617
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 4 | kernel-0:2.6.9-42.0.2.EL | Fixed | RHSA-2006:0617 |
No package ranges for this CVE.
Remediation
Red Hat statement
This vulnerability does not affect Red Hat Enterprise Linux 2.1 or 3 as they are based on 2.4 kernels. The exploit relies on the kernel supporting the a.out binary format. Red Hat Enterprise Linux 4, Fedora Core 4, and Fedora Core 5 do not support the a.out binary format, causing the exploit to fail. We are not currently aware of any way to exploit this vulnerability if a.out binary format is not enabled. In addition, a default installation of these OS enables SELinux in enforcing mode. SELinux also completely blocks attempts to exploit this issue. https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=198973#c10
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
No CVSS v3.0 score for this CVE.
AV:L/AC:H/Au:N/C:C/I:C/A:C
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 2, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (10 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 2, 2026 | 2.20% (0.02203) | 81.92th | v5 (v2026.06.15) |
| Jun 15, 2026 | 2.20% (0.02203) | 80.16th | v5 (v2026.06.15) |
| Mar 17, 2025 | 0.07% (0.00075) | 20.20th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.07% (0.00065) | 30.54th | v3 (v2023.03.01) |
| Sep 9, 2023 | 0.07% (0.00066) | 27.42th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.04% (0.00044) | 8.24th | v3 (v2023.03.01) |
| Mar 6, 2023 | 1.55% (0.01547) | 74.98th | v2 (v2022.01.01) |
| Feb 23, 2023 | 1.55% (0.01547) | 74.94th | v2 (v2022.01.01) |
| Apr 1, 2022 | 1.55% (0.01547) | 72.92th | v2 (v2022.01.01) |
| Feb 4, 2022 | 1.55% (0.01547) | 51.82th | v2 (v2022.01.01) |
No CWE recorded.
References (33)
- http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.17.5 x_refsource_CONFIRM
- http://lists.grok.org.uk/pipermail/full-disclosure/2006-July/047907.html mailing-listx_refsource_FULLDISC
- http://secunia.com/advisories/21041 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/21057 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/21073 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/21119 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/21123 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/21179 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/21498 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/21605 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/22174 third-party-advisoryx_refsource_SECUNIA
- http://support.avaya.com/elmodocs2/security/ASA-2006-203.htm x_refsource_CONFIRM
- http://www.debian.org/security/2006/dsa-1111 vendor-advisoryx_refsource_DEBIAN
- http://www.kernel.org/git/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=blobdiff%3Bh=0cb8f20d000c25118947fcafa81606300ced35f8%3Bhp=243a94af0427b2630fb85f489a5419410dac3bfc%3Bhb=18b0bbd8ca6d3cb90425aa0d77b99a762c6d6de3%3Bf=fs/proc/base.c x_refsource_CONFIRM
- http://www.mandriva.com/security/advisories?name=MDKSA-2006:124 vendor-advisoryx_refsource_MANDRIVA
- http://www.novell.com/linux/security/advisories/2006_17_sr.html vendor-advisoryx_refsource_SUSE
- http://www.novell.com/linux/security/advisories/2006_42_kernel.html vendor-advisoryx_refsource_SUSE
- http://www.novell.com/linux/security/advisories/2006_47_kernel.html vendor-advisoryx_refsource_SUSE
- http://www.novell.com/linux/security/advisories/2006_49_kernel.html vendor-advisoryx_refsource_SUSE
- http://www.osvdb.org/27120 vdb-entryx_refsource_OSVDB
- http://www.redhat.com/support/errata/RHSA-2006-0617.html vendor-advisoryx_refsource_REDHAT
- http://www.securityfocus.com/archive/1/440300/100/0/threaded mailing-listx_refsource_BUGTRAQ
- http://www.securityfocus.com/bid/18992 vdb-entryx_refsource_BID
- http://www.ubuntu.com/usn/usn-319-2 vendor-advisoryx_refsource_UBUNTU
- http://www.vupen.com/english/advisories/2006/2816 vdb-entryx_refsource_VUPEN
- https://access.redhat.com/security/cve/CVE-2006-3626 Vendor Advisory
- https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=198973 x_refsource_CONFIRM
- https://bugzilla.redhat.com/show_bug.cgi?id=1618145 Issue Tracking
- https://exchange.xforce.ibmcloud.com/vulnerabilities/27790 vdb-entryx_refsource_XF
- https://nvd.nist.gov/vuln/detail/CVE-2006-3626
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10060 vdb-entrysignaturex_refsource_OVAL
- https://usn.ubuntu.com/319-1/ vendor-advisoryx_refsource_UBUNTU
- https://www.cve.org/CVERecord?id=CVE-2006-3626
Change history (0)
No recorded changes yet.