security flaw
Published Oct 9, 2006
7.5
HIGHCVSS 3.1
EPSS 4.87%
Description
The clip_mkip function in net/atm/clip.c of the ATM subsystem in Linux kernel allows remote attackers to cause a denial of service (panic) via unknown vectors that cause the ATM subsystem to access the memory of socket buffers after they are freed (freed pointer dereference).
Affected products
No data.
Configuration 1
- < 2.6.18
Configuration 2
- 5.10
- 6.06
- 6.10
Configuration 3
- 2.1
- 3
- 4
No data.
Red Hat Enterprise Linux 2.1
kernel-0:2.4.18-e.64
Fixed · RHSA-2007:0012
Red Hat Enterprise Linux 2.1
kernel-0:2.4.9-e.71
Fixed · RHSA-2007:0013
Red Hat Enterprise Linux 3
kernel-0:2.4.21-47.0.1.EL
Fixed · RHSA-2006:0710
Red Hat Enterprise Linux 4
kernel-0:2.6.9-42.0.3.EL
Fixed · RHSA-2006:0689
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 2.1 | kernel-0:2.4.18-e.64 | Fixed | RHSA-2007:0012 |
| Red Hat Enterprise Linux 2.1 | kernel-0:2.4.9-e.71 | Fixed | RHSA-2007:0013 |
| Red Hat Enterprise Linux 3 | kernel-0:2.4.21-47.0.1.EL | Fixed | RHSA-2006:0710 |
| Red Hat Enterprise Linux 4 | kernel-0:2.6.9-42.0.3.EL | Fixed | RHSA-2006:0689 |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
No CVSS v3.0 score for this CVE.
AV:N/AC:M/Au:N/C:N/I:N/A:C
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 3, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (20 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 3, 2026 | 4.87% (0.04870) | 91.79th | v5 (v2026.06.15) |
| Jun 15, 2026 | 4.60% (0.04601) | 90.43th | v5 (v2026.06.15) |
| Jul 20, 2025 | 35.02% (0.35021) | 96.84th | v4 (v2025.03.14) |
| Mar 30, 2025 | 30.00% (0.29998) | 96.25th | v4 (v2025.03.14) |
| Mar 29, 2025 | 23.63% (0.23627) | 93.55th | v4 (v2025.03.14) |
| Mar 19, 2025 | 30.00% (0.29998) | 96.06th | v4 (v2025.03.14) |
| Mar 17, 2025 | 22.86% (0.22864) | 95.43th | v4 (v2025.03.14) |
| Dec 17, 2024 | 2.26% (0.02261) | 89.25th | v3 (v2023.03.01) |
| Feb 10, 2024 | 5.58% (0.05581) | 92.97th | v3 (v2023.03.01) |
| Dec 5, 2023 | 3.97% (0.03966) | 91.05th | v3 (v2023.03.01) |
| Nov 8, 2023 | 4.77% (0.04774) | 91.81th | v3 (v2023.03.01) |
| Sep 20, 2023 | 7.46% (0.07456) | 93.32th | v3 (v2023.03.01) |
| Aug 13, 2023 | 7.36% (0.07364) | 93.20th | v3 (v2023.03.01) |
| Jul 6, 2023 | 5.69% (0.05687) | 92.22th | v3 (v2023.03.01) |
| May 29, 2023 | 5.96% (0.05959) | 92.33th | v3 (v2023.03.01) |
| Mar 13, 2023 | 5.76% (0.05760) | 92.15th | v3 (v2023.03.01) |
| Mar 7, 2023 | 5.52% (0.05516) | 92.01th | v3 (v2023.03.01) |
| Mar 6, 2023 | 3.93% (0.03932) | 85.88th | v2 (v2022.01.01) |
| Apr 1, 2022 | 3.93% (0.03932) | 84.43th | v2 (v2022.01.01) |
| Feb 4, 2022 | 3.93% (0.03932) | 67.70th | v2 (v2022.01.01) |
References (42)
- http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=206265 x_refsource_CONFIRMExploitIssue Tracking
- http://secunia.com/advisories/22253 third-party-advisoryx_refsource_SECUNIABroken LinkVendor Advisory
- http://secunia.com/advisories/22279 third-party-advisoryx_refsource_SECUNIABroken LinkPatchVendor Advisory
- http://secunia.com/advisories/22292 third-party-advisoryx_refsource_SECUNIABroken LinkPatchVendor Advisory
- http://secunia.com/advisories/22497 third-party-advisoryx_refsource_SECUNIABroken Link
- http://secunia.com/advisories/22762 third-party-advisoryx_refsource_SECUNIABroken Link
- http://secunia.com/advisories/22945 third-party-advisoryx_refsource_SECUNIABroken Link
- http://secunia.com/advisories/23064 third-party-advisoryx_refsource_SECUNIABroken Link
- http://secunia.com/advisories/23370 third-party-advisoryx_refsource_SECUNIABroken Link
- http://secunia.com/advisories/23384 third-party-advisoryx_refsource_SECUNIABroken Link
- http://secunia.com/advisories/23395 third-party-advisoryx_refsource_SECUNIABroken Link
- http://secunia.com/advisories/23474 third-party-advisoryx_refsource_SECUNIABroken Link
- http://secunia.com/advisories/23752 third-party-advisoryx_refsource_SECUNIABroken Link
- http://secunia.com/advisories/23788 third-party-advisoryx_refsource_SECUNIABroken Link
- http://secunia.com/advisories/24288 third-party-advisoryx_refsource_SECUNIABroken Link
- http://secunia.com/advisories/25691 third-party-advisoryx_refsource_SECUNIABroken Link
- http://securitytracker.com/id?1017526 vdb-entryx_refsource_SECTRACKBroken LinkThird Party AdvisoryVDB Entry
- http://support.avaya.com/elmodocs2/security/ASA-2006-249.htm x_refsource_CONFIRMThird Party Advisory
- http://support.avaya.com/elmodocs2/security/ASA-2006-254.htm x_refsource_CONFIRMThird Party Advisory
- http://support.avaya.com/elmodocs2/security/ASA-2007-078.htm x_refsource_CONFIRMThird Party Advisory
- http://www.kernel.org/git/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=fe26109a9dfd9327fdbe630fc819e1b7450986b2 x_refsource_CONFIRMBroken Link
- http://www.mandriva.com/security/advisories?name=MDKSA-2006:197 vendor-advisoryx_refsource_MANDRIVABroken Link
- http://www.mandriva.com/security/advisories?name=MDKSA-2007:012 vendor-advisoryx_refsource_MANDRIVABroken Link
- http://www.mandriva.com/security/advisories?name=MDKSA-2007:025 vendor-advisoryx_refsource_MANDRIVABroken Link
- http://www.novell.com/linux/security/advisories/2006_79_kernel.html vendor-advisoryx_refsource_SUSEBroken Link
- http://www.redhat.com/support/errata/RHSA-2006-0689.html vendor-advisoryx_refsource_REDHATBroken LinkPatch
- http://www.redhat.com/support/errata/RHSA-2006-0710.html vendor-advisoryx_refsource_REDHATBroken Link
- http://www.redhat.com/support/errata/RHSA-2007-0012.html vendor-advisoryx_refsource_REDHATBroken Link
- http://www.redhat.com/support/errata/RHSA-2007-0013.html vendor-advisoryx_refsource_REDHATBroken Link
- http://www.securityfocus.com/archive/1/471457 mailing-listx_refsource_BUGTRAQBroken LinkThird Party AdvisoryVDB Entry
- http://www.securityfocus.com/bid/20363 vdb-entryx_refsource_BIDBroken LinkThird Party AdvisoryVDB Entry
- http://www.ubuntu.com/usn/usn-395-1 vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- http://www.us.debian.org/security/2006/dsa-1233 vendor-advisoryx_refsource_DEBIANBroken Link
- http://www.us.debian.org/security/2006/dsa-1237 vendor-advisoryx_refsource_DEBIANBroken Link
- http://www.vupen.com/english/advisories/2006/3937 vdb-entryx_refsource_VUPENBroken Link
- http://www.vupen.com/english/advisories/2006/3999 vdb-entryx_refsource_VUPENBroken Link
- https://access.redhat.com/security/cve/CVE-2006-4997 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1618207 Issue Tracking
- https://exchange.xforce.ibmcloud.com/vulnerabilities/29387 vdb-entryx_refsource_XFThird Party AdvisoryVDB Entry
- https://nvd.nist.gov/vuln/detail/CVE-2006-4997
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10388 vdb-entrysignaturex_refsource_OVALBroken Link
- https://www.cve.org/CVERecord?id=CVE-2006-4997
Change history (0)
No recorded changes yet.