CVE-2006-1524
Summary
| CVE | CVE-2006-1524 |
|---|---|
| State | PUBLISHED |
| Assigner | redhat |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2006-04-19 18:18:00 UTC |
| Updated | 2025-04-03 01:03:51 UTC |
| Description | madvise_remove in Linux kernel 2.6.16 up to 2.6.16.6 does not follow file and mmap restrictions, which allows local users to bypass IPC permissions and replace portions of readonly tmpfs files with zeroes, aka the MADV_REMOVE vulnerability. NOTE: this description was originally written in a way that combined two separate issues. The mprotect issue now has a separate name, CVE-2006-2071. |
Risk And Classification
Primary CVSS: v2.0 3.6 from [email protected]
AV:L/AC:L/Au:N/C:P/I:P/A:N
EPSS: 0.000660000 probability, percentile 0.202640000 (date 2026-04-20)
Problem Types: CWE-264 | n/a
CVSS v2.0 Breakdown
Access Vector
LocalAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
NoneAV:L/AC:L/Au:N/C:P/I:P/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Linux | Linux Kernel | 2.6.16 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.16.1 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.16.2 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.16.3 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.16.4 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.16.5 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.16.6 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Linux Kernel Shared Memory Restrictions Bypass - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| www.osvdb.org/24714 | af854a3a-2127-422b-91ae-364da2661108 | www.osvdb.org | |
| LWN: Fedora alert FEDORA-2006-423 (kernel) | af854a3a-2127-422b-91ae-364da2661108 | lwn.net | |
| Webmail - OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Vendor Advisory |
| 404: File not found | af854a3a-2127-422b-91ae-364da2661108 | kernel.org | |
| Webmail - OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Vendor Advisory |
| Debian -- Security Information -- DSA-1097-1 kernel-source-2.4.27 | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | |
| Debian -- Security Information -- DSA-1103-1 kernel-source-2.6.8 | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| Linux Kernel Shared Memory Restrictions Bypass - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Patch, Vendor Advisory |
| Security Announcement | af854a3a-2127-422b-91ae-364da2661108 | www.novell.com | |
| SUSE update for kernel - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| Fedora update for kernel - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| Debian update for kernel-source-2.4.27 - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| Debian update for kernel-source-2.6.8 - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Vendor Advisory |
| Linux Kernel Shared Memory Security Restriction Bypass Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Patch |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.