The isdn_ppp_ccp_reset_alloc_state function in drivers/isdn/isdn_ppp.c in the Linux 2.4 kernel before 2.4.34-rc4 does not call the init_timer function for the ISDN PPP CCP reset state timer, which has unknown attack vectors and results in a system crash
Published Jan 4, 2007
1.7
LOWCVSS 2.0
EPSS 0.38%
Description
The isdn_ppp_ccp_reset_alloc_state function in drivers/isdn/isdn_ppp.c in the Linux 2.4 kernel before 2.4.34-rc4 does not call the init_timer function for the ISDN PPP CCP reset state timer, which has unknown attack vectors and results in a system crash.
Affected products
No data.
- ≤ 2.4.34
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Red Hat statement
Red Hat Enterprise Linux 5 is not vulnerable to this issue as it contains a backported patch.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
No CVSS v3.0 score for this CVE.
AV:L/AC:L/Au:S/C:N/I:N/A:P
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 2, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (11 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 2, 2026 | 0.38% (0.00376) | 29.26th | v5 (v2026.06.15) |
| Jun 15, 2026 | 0.36% (0.00355) | 27.19th | v5 (v2026.06.15) |
| Mar 17, 2025 | 0.07% (0.00068) | 18.09th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.10% (0.00105) | 44.69th | v3 (v2023.03.01) |
| Mar 1, 2024 | 0.11% (0.00108) | 42.57th | v3 (v2023.03.01) |
| Aug 23, 2023 | 0.07% (0.00072) | 29.62th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.06% (0.00064) | 26.16th | v3 (v2023.03.01) |
| Mar 6, 2023 | 1.55% (0.01547) | 74.98th | v2 (v2022.01.01) |
| Feb 23, 2023 | 1.55% (0.01547) | 74.94th | v2 (v2022.01.01) |
| Apr 1, 2022 | 1.55% (0.01547) | 72.92th | v2 (v2022.01.01) |
| Feb 4, 2022 | 1.55% (0.01547) | 51.82th | v2 (v2022.01.01) |
No CWE recorded.
References (26)
- http://kernel.org/pub/linux/kernel/v2.4/ChangeLog-2.4.34 x_refsource_CONFIRM
- http://secunia.com/advisories/23529 third-party-advisoryx_refsource_SECUNIAPatch
- http://secunia.com/advisories/23609 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/23752 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/24098 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/24100 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/24547 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/25226 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/25683 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/25691 third-party-advisoryx_refsource_SECUNIA
- http://www.kernel.org/git/?p=linux/kernel/git/wtarreau/linux-2.4.git%3Ba=commitdiff%3Bh=05dca9b77f99d80cf615075624666106d5b61727 x_refsource_CONFIRM
- http://www.mandriva.com/security/advisories?name=MDKSA-2007:012 vendor-advisoryx_refsource_MANDRIVA
- http://www.mandriva.com/security/advisories?name=MDKSA-2007:025 vendor-advisoryx_refsource_MANDRIVA
- http://www.mandriva.com/security/advisories?name=MDKSA-2007:040 vendor-advisoryx_refsource_MANDRIVA
- http://www.novell.com/linux/security/advisories/2007_18_kernel.html vendor-advisoryx_refsource_SUSE
- http://www.novell.com/linux/security/advisories/2007_21_kernel.html vendor-advisoryx_refsource_SUSE
- http://www.novell.com/linux/security/advisories/2007_30_kernel.html vendor-advisoryx_refsource_SUSE
- http://www.novell.com/linux/security/advisories/2007_35_kernel.html vendor-advisoryx_refsource_SUSE
- http://www.securityfocus.com/archive/1/471457 mailing-listx_refsource_BUGTRAQ
- http://www.securityfocus.com/bid/21835 vdb-entryx_refsource_BID
- http://www.securityfocus.com/bid/21883 vdb-entryx_refsource_BID
- http://www.trustix.org/errata/2007/0002/ vendor-advisoryx_refsource_TRUSTIX
- http://www.ubuntu.com/usn/usn-416-1 vendor-advisoryx_refsource_UBUNTU
- https://access.redhat.com/security/cve/CVE-2006-5749 Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2006-5749
- https://www.cve.org/CVERecord?id=CVE-2006-5749
Change history (0)
No recorded changes yet.