VulnerabilityModified
CVE-2006-4813
The __block_prepare_write function in fs/buffer.c for Linux kernel 2.6.x before 2.6.13 does not properly clear buffers during certain error conditions, which allows local users to read portions of files that have been unlinked.
LOW 2.1EPSS 0.41%
Does this matter?
Lower severity and a low EPSS score (0.41%). Track it; it rarely justifies an emergency change on its own.
Description
The __block_prepare_write function in fs/buffer.c for Linux kernel 2.6.x before 2.6.13 does not properly clear buffers during certain error conditions, which allows local users to read portions of files that have been unlinked.
- CVSS 2.0
- 2.1 LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 0.41% probability · 35th percentile
- CISA KEV
- Not listed
- Affected
- linux/linux kernel
- Source
- secalert@redhat.com
References
- http://osvdb.org/31376
- http://rhn.redhat.com/errata/RHSA-2007-0014.html
- http://secunia.com/advisories/23370
- http://secunia.com/advisories/23384
- http://secunia.com/advisories/23474
- http://secunia.com/advisories/23752
- http://secunia.com/advisories/23997
- http://secunia.com/advisories/24206
- http://support.avaya.com/elmodocs2/security/ASA-2007-063.htm
- http://www.kernel.org/git/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=152becd26e0563aefdbc4fd1fe491928efe92d1f
- http://www.mandriva.com/security/advisories?name=MDKSA-2007:012
- http://www.mandriva.com/security/advisories?name=MDKSA-2007:025
- http://www.novell.com/linux/security/advisories/2006_79_kernel.html
- http://www.securityfocus.com/bid/21522
- http://www.ubuntu.com/usn/usn-395-1
- http://www.us.debian.org/security/2006/dsa-1233
- https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=207463Patch
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11701
- http://osvdb.org/31376
- http://rhn.redhat.com/errata/RHSA-2007-0014.html
- http://secunia.com/advisories/23370
- http://secunia.com/advisories/23384
- http://secunia.com/advisories/23474
- http://secunia.com/advisories/23752
- http://secunia.com/advisories/23997
- http://secunia.com/advisories/24206
- http://support.avaya.com/elmodocs2/security/ASA-2007-063.htm
- http://www.kernel.org/git/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=152becd26e0563aefdbc4fd1fe491928efe92d1f
- http://www.mandriva.com/security/advisories?name=MDKSA-2007:012
- http://www.mandriva.com/security/advisories?name=MDKSA-2007:025
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.