{"api_version":"1","generated_at":"2026-07-23T14:51:48+00:00","cve":"CVE-2006-1524","urls":{"html":"https://cve.report/CVE-2006-1524","api":"https://cve.report/api/cve/CVE-2006-1524.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2006-1524","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2006-1524"},"summary":{"title":"CVE-2006-1524","description":"madvise_remove in Linux kernel 2.6.16 up to 2.6.16.6 does not follow file and mmap restrictions, which allows local users to bypass IPC permissions and replace portions of readonly tmpfs files with zeroes, aka the MADV_REMOVE vulnerability.  NOTE: this description was originally written in a way that combined two separate issues.  The mprotect issue now has a separate name, CVE-2006-2071.","state":"PUBLISHED","assigner":"redhat","published_at":"2006-04-19 18:18:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["CWE-264","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"3.6","severity":"","vector":"AV:L/AC:L/Au:N/C:P/I:P/A:N","data":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:P/I:P/A:N","baseScore":3.6,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"NONE"}}],"references":[{"url":"http://secunia.com/advisories/19664","name":"http://secunia.com/advisories/19664","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Linux Kernel Shared Memory Restrictions Bypass - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.osvdb.org/24714","name":"http://www.osvdb.org/24714","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://lwn.net/Alerts/180820/","name":"http://lwn.net/Alerts/180820/","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"LWN: Fedora alert FEDORA-2006-423 (kernel)","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2006/1391","name":"http://www.vupen.com/english/advisories/2006/1391","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Webmail - OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.16.6","name":"http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.16.6","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"404: File not found","mime":"text/plain","httpstatus":"404","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2006/2554","name":"http://www.vupen.com/english/advisories/2006/2554","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Webmail - OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.debian.org/security/2006/dsa-1097","name":"http://www.debian.org/security/2006/dsa-1097","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Debian -- Security Information -- DSA-1097-1 kernel-source-2.4.27","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.debian.org/security/2006/dsa-1103","name":"http://www.debian.org/security/2006/dsa-1103","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Debian -- Security Information -- DSA-1103-1 kernel-source-2.6.8","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/25870","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/25870","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/19657","name":"http://secunia.com/advisories/19657","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"Linux Kernel Shared Memory Restrictions Bypass - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.novell.com/linux/security/advisories/2006-05-31.html","name":"http://www.novell.com/linux/security/advisories/2006-05-31.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Security Announcement","mime":"text/html","httpstatus":"404","archivestatus":"200"},{"url":"http://secunia.com/advisories/20398","name":"http://secunia.com/advisories/20398","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"SUSE update for kernel - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/19735","name":"http://secunia.com/advisories/19735","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Fedora update for kernel - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/20671","name":"http://secunia.com/advisories/20671","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Debian update for kernel-source-2.4.27 - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/20914","name":"http://secunia.com/advisories/20914","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Debian update for kernel-source-2.6.8 - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2006/1475","name":"http://www.vupen.com/english/advisories/2006/1475","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/17587","name":"http://www.securityfocus.com/bid/17587","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"],"title":"Linux Kernel Shared Memory Security Restriction Bypass Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2006-1524","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2006-1524","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2006","cve_id":"1524","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"linux","cpe5":"linux_kernel","cpe6":"2.6.16","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2006","cve_id":"1524","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"linux","cpe5":"linux_kernel","cpe6":"2.6.16.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2006","cve_id":"1524","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"linux","cpe5":"linux_kernel","cpe6":"2.6.16.2","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2006","cve_id":"1524","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"linux","cpe5":"linux_kernel","cpe6":"2.6.16.3","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2006","cve_id":"1524","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"linux","cpe5":"linux_kernel","cpe6":"2.6.16.4","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2006","cve_id":"1524","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"linux","cpe5":"linux_kernel","cpe6":"2.6.16.5","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2006","cve_id":"1524","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"linux","cpe5":"linux_kernel","cpe6":"2.6.16.6","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2006","cve_id":"1524","cve":"CVE-2006-1524","epss":"0.000660000","percentile":"0.202640000","score_date":"2026-04-20","updated_at":"2026-04-21 00:07:48"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T17:12:22.161Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"linux-madvise-security-bypass(25870)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/25870"},{"name":"19735","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/19735"},{"name":"ADV-2006-2554","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2006/2554"},{"name":"ADV-2006-1391","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2006/1391"},{"name":"19664","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/19664"},{"name":"FEDORA-2006-423","tags":["vendor-advisory","x_refsource_FEDORA","x_transferred"],"url":"http://lwn.net/Alerts/180820/"},{"name":"DSA-1097","tags":["vendor-advisory","x_refsource_DEBIAN","x_transferred"],"url":"http://www.debian.org/security/2006/dsa-1097"},{"name":"SUSE-SA:2006:028","tags":["vendor-advisory","x_refsource_SUSE","x_transferred"],"url":"http://www.novell.com/linux/security/advisories/2006-05-31.html"},{"name":"DSA-1103","tags":["vendor-advisory","x_refsource_DEBIAN","x_transferred"],"url":"http://www.debian.org/security/2006/dsa-1103"},{"name":"24714","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://www.osvdb.org/24714"},{"name":"17587","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/17587"},{"name":"ADV-2006-1475","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2006/1475"},{"name":"20398","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/20398"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.16.6"},{"name":"19657","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/19657"},{"name":"20671","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/20671"},{"name":"20914","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/20914"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2006-04-17T00:00:00.000Z","descriptions":[{"lang":"en","value":"madvise_remove in Linux kernel 2.6.16 up to 2.6.16.6 does not follow file and mmap restrictions, which allows local users to bypass IPC permissions and replace portions of readonly tmpfs files with zeroes, aka the MADV_REMOVE vulnerability.  NOTE: this description was originally written in a way that combined two separate issues.  The mprotect issue now has a separate name, CVE-2006-2071."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-07-19T15:57:01.000Z","orgId":"53f830b8-0a3f-465b-8143-3b8a9948e749","shortName":"redhat"},"references":[{"name":"linux-madvise-security-bypass(25870)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/25870"},{"name":"19735","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/19735"},{"name":"ADV-2006-2554","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2006/2554"},{"name":"ADV-2006-1391","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2006/1391"},{"name":"19664","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/19664"},{"name":"FEDORA-2006-423","tags":["vendor-advisory","x_refsource_FEDORA"],"url":"http://lwn.net/Alerts/180820/"},{"name":"DSA-1097","tags":["vendor-advisory","x_refsource_DEBIAN"],"url":"http://www.debian.org/security/2006/dsa-1097"},{"name":"SUSE-SA:2006:028","tags":["vendor-advisory","x_refsource_SUSE"],"url":"http://www.novell.com/linux/security/advisories/2006-05-31.html"},{"name":"DSA-1103","tags":["vendor-advisory","x_refsource_DEBIAN"],"url":"http://www.debian.org/security/2006/dsa-1103"},{"name":"24714","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://www.osvdb.org/24714"},{"name":"17587","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/17587"},{"name":"ADV-2006-1475","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2006/1475"},{"name":"20398","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/20398"},{"tags":["x_refsource_CONFIRM"],"url":"http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.16.6"},{"name":"19657","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/19657"},{"name":"20671","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/20671"},{"name":"20914","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/20914"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"secalert@redhat.com","ID":"CVE-2006-1524","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"madvise_remove in Linux kernel 2.6.16 up to 2.6.16.6 does not follow file and mmap restrictions, which allows local users to bypass IPC permissions and replace portions of readonly tmpfs files with zeroes, aka the MADV_REMOVE vulnerability.  NOTE: this description was originally written in a way that combined two separate issues.  The mprotect issue now has a separate name, CVE-2006-2071."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"linux-madvise-security-bypass(25870)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/25870"},{"name":"19735","refsource":"SECUNIA","url":"http://secunia.com/advisories/19735"},{"name":"ADV-2006-2554","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2006/2554"},{"name":"ADV-2006-1391","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2006/1391"},{"name":"19664","refsource":"SECUNIA","url":"http://secunia.com/advisories/19664"},{"name":"FEDORA-2006-423","refsource":"FEDORA","url":"http://lwn.net/Alerts/180820/"},{"name":"DSA-1097","refsource":"DEBIAN","url":"http://www.debian.org/security/2006/dsa-1097"},{"name":"SUSE-SA:2006:028","refsource":"SUSE","url":"http://www.novell.com/linux/security/advisories/2006-05-31.html"},{"name":"DSA-1103","refsource":"DEBIAN","url":"http://www.debian.org/security/2006/dsa-1103"},{"name":"24714","refsource":"OSVDB","url":"http://www.osvdb.org/24714"},{"name":"17587","refsource":"BID","url":"http://www.securityfocus.com/bid/17587"},{"name":"ADV-2006-1475","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2006/1475"},{"name":"20398","refsource":"SECUNIA","url":"http://secunia.com/advisories/20398"},{"name":"http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.16.6","refsource":"CONFIRM","url":"http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.16.6"},{"name":"19657","refsource":"SECUNIA","url":"http://secunia.com/advisories/19657"},{"name":"20671","refsource":"SECUNIA","url":"http://secunia.com/advisories/20671"},{"name":"20914","refsource":"SECUNIA","url":"http://secunia.com/advisories/20914"}]}}}},"cveMetadata":{"assignerOrgId":"53f830b8-0a3f-465b-8143-3b8a9948e749","assignerShortName":"redhat","cveId":"CVE-2006-1524","datePublished":"2006-04-19T18:00:00.000Z","dateReserved":"2006-03-30T00:00:00.000Z","dateUpdated":"2024-08-07T17:12:22.161Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2006-04-19 18:18:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["CWE-264","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:P/I:P/A:N","baseScore":3.6,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"LOW","exploitabilityScore":3.9,"impactScore":4.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:2.6.16:*:*:*:*:*:*:*","matchCriteriaId":"34E60197-56C3-485C-9609-B1C4A0E0FCB2"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:2.6.16.1:*:*:*:*:*:*:*","matchCriteriaId":"86E452E4-45A9-4469-BF69-F40B6598F0EA"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:2.6.16.2:*:*:*:*:*:*:*","matchCriteriaId":"C5751AC4-A60F-42C6-88E5-FC8CFEE6F696"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:2.6.16.3:*:*:*:*:*:*:*","matchCriteriaId":"1FF886A6-7E73-47AD-B6A5-A9EC5BEDCD0C"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:2.6.16.4:*:*:*:*:*:*:*","matchCriteriaId":"48777A01-8F36-4752-8F7A-1D1686C69A33"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:2.6.16.5:*:*:*:*:*:*:*","matchCriteriaId":"42DA6A18-5AA1-4920-94C6-8D0BB73C5352"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:2.6.16.6:*:*:*:*:*:*:*","matchCriteriaId":"992EA5DE-5A5B-4782-8B5A-BDD8D6FB1E31"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2006","CveId":"1524","Ordinal":"1","Title":"CVE-2006-1524","CVE":"CVE-2006-1524","Year":"2006"},"notes":[{"CveYear":"2006","CveId":"1524","Ordinal":"1","NoteData":"madvise_remove in Linux kernel 2.6.16 up to 2.6.16.6 does not follow file and mmap restrictions, which allows local users to bypass IPC permissions and replace portions of readonly tmpfs files with zeroes, aka the MADV_REMOVE vulnerability.  NOTE: this description was originally written in a way that combined two separate issues.  The mprotect issue now has a separate name, CVE-2006-2071.","Type":"Description","Title":"CVE-2006-1524"},{"CveYear":"2006","CveId":"1524","Ordinal":"2","NoteData":"2006-04-19","Type":"Other","Title":"Published"},{"CveYear":"2006","CveId":"1524","Ordinal":"3","NoteData":"2017-07-19","Type":"Other","Title":"Modified"}]}}}