CVE-2006-4997
The clip_mkip function in net/atm/clip.c of the ATM subsystem in Linux kernel allows remote attackers to cause a denial of service (panic) via unknown vectors that cause the ATM subsystem to access the memory of socket buffers after they are freed…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (4.87%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The clip_mkip function in net/atm/clip.c of the ATM subsystem in Linux kernel allows remote attackers to cause a denial of service (panic) via unknown vectors that cause the ATM subsystem to access the memory of socket buffers after they are freed (freed pointer dereference).
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 4.87% probability · 92th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-416
- Affected
- linux/linux kernel · canonical/ubuntu linux · redhat/enterprise linux
- Source
- cve@mitre.org
References
- http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=206265Exploit, Issue Tracking
- http://secunia.com/advisories/22253Broken Link, Vendor Advisory
- http://secunia.com/advisories/22279Broken Link, Patch, Vendor Advisory
- http://secunia.com/advisories/22292Broken Link, Patch, Vendor Advisory
- http://secunia.com/advisories/22497Broken Link
- http://secunia.com/advisories/22762Broken Link
- http://secunia.com/advisories/22945Broken Link
- http://secunia.com/advisories/23064Broken Link
- http://secunia.com/advisories/23370Broken Link
- http://secunia.com/advisories/23384Broken Link
- http://secunia.com/advisories/23395Broken Link
- http://secunia.com/advisories/23474Broken Link
- http://secunia.com/advisories/23752Broken Link
- http://secunia.com/advisories/23788Broken Link
- http://secunia.com/advisories/24288Broken Link
- http://secunia.com/advisories/25691Broken Link
- http://securitytracker.com/id?1017526Broken Link, Third Party Advisory, VDB Entry
- http://support.avaya.com/elmodocs2/security/ASA-2006-249.htmThird Party Advisory
- http://support.avaya.com/elmodocs2/security/ASA-2006-254.htmThird Party Advisory
- http://support.avaya.com/elmodocs2/security/ASA-2007-078.htmThird Party Advisory
- http://www.kernel.org/git/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=fe26109a9dfd9327fdbe630fc819e1b7450986b2Broken Link
- http://www.mandriva.com/security/advisories?name=MDKSA-2006:197Broken Link
- http://www.mandriva.com/security/advisories?name=MDKSA-2007:012Broken Link
- http://www.mandriva.com/security/advisories?name=MDKSA-2007:025Broken Link
- http://www.novell.com/linux/security/advisories/2006_79_kernel.htmlBroken Link
- http://www.redhat.com/support/errata/RHSA-2006-0689.htmlBroken Link, Patch
- http://www.redhat.com/support/errata/RHSA-2006-0710.htmlBroken Link
- http://www.redhat.com/support/errata/RHSA-2007-0012.htmlBroken Link
- http://www.redhat.com/support/errata/RHSA-2007-0013.htmlBroken Link
- http://www.securityfocus.com/archive/1/471457Broken Link, Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.