SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2006-1342

net/ipv4/af_inet.c in Linux kernel 2.4 does not clear sockaddr_in.sin_zero before returning IPv4 socket names from the (1) getsockname, (2) getpeername, and (3) accept functions, which allows local users to obtain portions of potentially sensitive memory.

LOW 2.1EPSS 0.73%

Does this matter?

Lower severity and a low EPSS score (0.73%). Track it; it rarely justifies an emergency change on its own.

Description

net/ipv4/af_inet.c in Linux kernel 2.4 does not clear sockaddr_in.sin_zero before returning IPv4 socket names from the (1) getsockname, (2) getpeername, and (3) accept functions, which allows local users to obtain portions of potentially sensitive memory.

CVSS 2.0
2.1 LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
EPSS
0.73% probability · 52th percentile
CISA KEV
Not listed
Affected
linux/linux kernel
Source
bc94ec7e-8909-4cbb-83df-d2fc9330fa88

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.