PT-2006-5448 · Linux · Linux Kernel

Published

2006-09-09

·

Updated

2025-01-17

·

CVE-2006-4663

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions 2.6.16 through 2.6.17.11
Description The issue concerns weak permissions in the source code tar archive of the Linux kernel, potentially allowing local users to insert malicious code that could be used during the next kernel compilation. However, it's noted that another researcher disputes this, finding no world-writable files or directories. The weak permissions might only be present under certain unusual or insecure scenarios.
Recommendations For Linux kernel versions 2.6.16 through 2.6.17.11, consider changing the permissions of the affected files and directories to prevent local users from inserting Trojan horse source code. As a temporary workaround, restrict access to the kernel compilation process to minimize the risk of exploitation.

Fix

Related Identifiers

CVE-2006-4663

Affected Products

Linux Kernel