VulnerabilityModified
CVE-2006-4814
The mincore function in the Linux kernel before 2.4.33.6 does not properly lock access to user space, which has unspecified impact and attack vectors, possibly related to a deadlock.
MEDIUM 4.6EPSS 1.01%
Does this matter?
Lower severity and a low EPSS score (1.01%). Track it; it rarely justifies an emergency change on its own.
Description
The mincore function in the Linux kernel before 2.4.33.6 does not properly lock access to user space, which has unspecified impact and attack vectors, possibly related to a deadlock.
- CVSS 2.0
- 4.6 MEDIUMAV:L/AC:L/Au:S/C:N/I:N/A:C
- EPSS
- 1.01% probability · 61th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-399
- Affected
- linux/linux kernel
- Source
- secalert@redhat.com
References
- http://lists.vmware.com/pipermail/security-announce/2008/000023.html
- http://rhn.redhat.com/errata/RHSA-2007-0014.html
- http://secunia.com/advisories/23436Vendor Advisory
- http://secunia.com/advisories/23609Vendor Advisory
- http://secunia.com/advisories/23997Vendor Advisory
- http://secunia.com/advisories/24098Vendor Advisory
- http://secunia.com/advisories/24100Vendor Advisory
- http://secunia.com/advisories/24206Vendor Advisory
- http://secunia.com/advisories/24482Vendor Advisory
- http://secunia.com/advisories/25691Vendor Advisory
- http://secunia.com/advisories/25714Vendor Advisory
- http://secunia.com/advisories/29058Vendor Advisory
- http://secunia.com/advisories/30110Vendor Advisory
- http://secunia.com/advisories/31246Vendor Advisory
- http://secunia.com/advisories/33280Vendor Advisory
- http://support.avaya.com/elmodocs2/security/ASA-2007-063.htm
- http://www.debian.org/security/2007/dsa-1304Patch
- http://www.debian.org/security/2008/dsa-1503Patch
- http://www.kernel.org/pub/linux/kernel/v2.4/ChangeLog-2.4.33.6
- http://www.mandriva.com/security/advisories?name=MDKSA-2007:040
- http://www.mandriva.com/security/advisories?name=MDKSA-2007:060
- http://www.novell.com/linux/security/advisories/2007_18_kernel.html
- http://www.redhat.com/support/errata/RHSA-2008-0211.html
- http://www.redhat.com/support/errata/RHSA-2008-0787.html
- http://www.securityfocus.com/archive/1/471457
- http://www.securityfocus.com/bid/21663Patch
- http://www.trustix.org/errata/2007/0002/
- http://www.ubuntu.com/usn/usn-416-1
- http://www.vupen.com/english/advisories/2006/5082Vendor Advisory
- http://www.vupen.com/english/advisories/2008/2222/referencesVendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.