CVE-2007-6417
Summary
| CVE | CVE-2007-6417 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2007-12-18 00:46:00 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | The shmem_getpage function (mm/shmem.c) in Linux kernel 2.6.11 through 2.6.23 does not properly clear allocated memory in some rare circumstances related to tmpfs, which might allow local users to read sensitive kernel data or cause a denial of service (crash). |
Risk And Classification
Primary CVSS: v2.0 7.2 from [email protected]
AV:L/AC:L/Au:N/C:C/I:C/A:C
Problem Types: CWE-200 | CWE-399 | n/a
CVSS v2.0 Breakdown
Access Vector
LocalAccess Complexity
LowAuthentication
NoneConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:L/AC:L/Au:N/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Linux | Linux Kernel | 2.6.11 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.12 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.13 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.14 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.15 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.16 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.17 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.18 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.19 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.20 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.21 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.22 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.23 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| SUSE update for kernel - Secunia Advisories - Vulnerability Intelligence - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| Debian -- Security Information -- DSA-1436-1 linux-2.6 | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | |
| Ubuntu update for kernel - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| Linux Kernel 'tmpfs' filesystem Local Security Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| 'Re: [PATCH] tmpfs: restore missing clear_highpage' - MARC | af854a3a-2127-422b-91ae-364da2661108 | marc.info | |
| USN-578-1: Linux kernel vulnerabilities | Ubuntu | af854a3a-2127-422b-91ae-364da2661108 | www.ubuntu.com | |
| Debian update for kernel - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| Support | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | |
| Red Hat update for kernel - Secunia Advisories - Vulnerability Intelligence - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| Repository / Oval Repository | af854a3a-2127-422b-91ae-364da2661108 | oval.cisecurity.org | |
| osvdb.org/44120 | af854a3a-2127-422b-91ae-364da2661108 | osvdb.org | |
| [security-announce] SUSE Security Announcement: Linux kernel (SUSE-SA:20 | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| Ubuntu update for kernel - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| 'Re: [PATCH] tmpfs: restore missing clear_highpage' - MARC | af854a3a-2127-422b-91ae-364da2661108 | marc.info | |
| '[PATCH] tmpfs: restore missing clear_highpage' - MARC | af854a3a-2127-422b-91ae-364da2661108 | marc.info | |
| Support / Security / Advisories / / MDVSA-2008:086 | Mandriva | af854a3a-2127-422b-91ae-364da2661108 | www.mandriva.com | |
| USN-574-1: Linux kernel vulnerabilities | Ubuntu | af854a3a-2127-422b-91ae-364da2661108 | www.ubuntu.com | |
| Support / Security / Advisories / / MDVSA-2008:112 | Mandriva | af854a3a-2127-422b-91ae-364da2661108 | www.mandriva.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
| Organization | Published | Contributor | Statement |
|---|---|---|---|
| Red Hat | 2009-01-15 | Tomas Hoger | This issue did not affect the versions of Linux kernel as shipped with Red Hat Enterprise Linux 2.1, 3, 4, and Red Hat Enterprise MRG. It was addressed in Red Hat Enterprise Linux 5 via: https://rhn.redhat.com/errata/RHSA-2008-0885.html |
There are currently no legacy QID mappings associated with this CVE.