VulnerabilityModified
CVE-2006-0744
Linux kernel before 2.6.16.5 does not properly handle uncanonical return addresses on Intel EM64T CPUs, which reports an exception in the SYSRET instead of the next instruction, which causes the kernel exception handler to run on the user stack with the…
MEDIUM 4.9EPSS 0.46%
Does this matter?
Lower severity and a low EPSS score (0.46%). Track it; it rarely justifies an emergency change on its own.
Description
Linux kernel before 2.6.16.5 does not properly handle uncanonical return addresses on Intel EM64T CPUs, which reports an exception in the SYSRET instead of the next instruction, which causes the kernel exception handler to run on the user stack with the wrong GS.
- CVSS 2.0
- 4.9 MEDIUMAV:L/AC:L/Au:N/C:N/I:N/A:C
- EPSS
- 0.46% probability · 39th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- linux/linux kernel
- Source
- secalert@redhat.com
References
- http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.16.5
- http://lwn.net/Alerts/180820/
- http://secunia.com/advisories/19639Vendor Advisory
- http://secunia.com/advisories/19735Vendor Advisory
- http://secunia.com/advisories/20157Vendor Advisory
- http://secunia.com/advisories/20237Vendor Advisory
- http://secunia.com/advisories/20398
- http://secunia.com/advisories/20716Vendor Advisory
- http://secunia.com/advisories/20914Vendor Advisory
- http://secunia.com/advisories/21136Vendor Advisory
- http://secunia.com/advisories/21179Vendor Advisory
- http://secunia.com/advisories/21498Vendor Advisory
- http://secunia.com/advisories/21745Vendor Advisory
- http://secunia.com/advisories/21983Vendor Advisory
- http://support.avaya.com/elmodocs2/security/ASA-2006-161.htm
- http://support.avaya.com/elmodocs2/security/ASA-2006-180.htm
- http://www.debian.org/security/2006/dsa-1103
- http://www.mandriva.com/security/advisories?name=MDKSA-2006:086
- http://www.mandriva.com/security/advisories?name=MDKSA-2006:150
- http://www.novell.com/linux/security/advisories/2006-05-31.html
- http://www.novell.com/linux/security/advisories/2006_42_kernel.html
- http://www.novell.com/linux/security/advisories/2006_47_kernel.html
- http://www.osvdb.org/24639
- http://www.redhat.com/support/errata/RHSA-2006-0437.html
- http://www.redhat.com/support/errata/RHSA-2006-0493.html
- http://www.securityfocus.com/bid/17541
- http://www.ubuntu.com/usn/usn-302-1
- http://www.vupen.com/english/advisories/2006/1390
- http://www.vupen.com/english/advisories/2006/1475
- http://www.vupen.com/english/advisories/2006/2554
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.