CVE-2006-5755
kernel: local denial of service due to NT bit leakage
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Linux kernel before 2.6.18, when running on x86_64 systems, does not properly save or restore EFLAGS during a context switch, which allows local users to cause a denial of service (crash) by causing SYSENTER to set an NT flag, which can trigger a crash on the IRET of the next task.
El núcleo de Linux anterior a 2.6.18, cuando se ejecuta en sistemas x86_64, no guarda o restaura adecuadamente las EFLAGS durante un cambio de contexto, lo cual permite a usuarios locales provocar una denegación de servicio (caída) provocando que SYSENTER active una bandera NT, lo que dispara una caída en el IRET de la siguiente tarea.
Several local vulnerabilities have been discovered in the Linux kernel that may lead to a denial of service or the execution of arbitrary code. This is an update to DSA-1381-1 which included only amd64 binaries for linux-2.6. Builds for all other architectures are now available, as well as rebuilds of ancillary packages that make use of the included linux source.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2006-11-06 CVE Reserved
- 2006-12-31 CVE Published
- 2024-08-07 CVE Updated
- 2025-03-19 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
CAPEC
References (18)
URL | Tag | Source |
---|---|---|
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commitdiff%3Bh=658fdbef66e5e9be79b457edc2cbbb3add840aa9 | X_refsource_confirm | |
http://kernel.org/git/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commitdiff%3Bh=658fdbef66e5e9be79b457edc2cbbb3add840aa9 | X_refsource_confirm | |
http://secunia.com/advisories/24098 | Third Party Advisory | |
http://secunia.com/advisories/25691 | Third Party Advisory | |
http://secunia.com/advisories/26620 | Third Party Advisory | |
http://secunia.com/advisories/26994 | Third Party Advisory | |
http://secunia.com/advisories/32485 | Third Party Advisory | |
http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.18 | X_refsource_confirm | |
http://www.kernel.org/pub/linux/kernel/v2.6/snapshots/patch-2.6.18-git13.log | X_refsource_confirm | |
http://www.securityfocus.com/archive/1/471457 | Mailing List | |
http://www.securityfocus.com/bid/26060 | Vdb Entry | |
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9554 | Signature |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://www.debian.org/security/2007/dsa-1381 | 2023-02-13 | |
http://www.mandriva.com/security/advisories?name=MDKSA-2007:171 | 2023-02-13 | |
http://www.redhat.com/support/errata/RHSA-2008-0957.html | 2023-02-13 | |
http://www.ubuntu.com/usn/usn-416-1 | 2023-02-13 | |
https://access.redhat.com/security/cve/CVE-2006-5755 | 2008-11-04 | |
https://bugzilla.redhat.com/show_bug.cgi?id=457718 | 2008-11-04 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | <= 2.6.17 Search vendor "Linux" for product "Linux Kernel" and version " <= 2.6.17" | - |
Affected
|