PT-2006-6701 · Linux+1 · Linux Kernel+1

Published

2006-11-22

·

Updated

2017-10-11

·

CVE-2006-6056

CVSS v2.0

4.9

Medium

VectorAV:L/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel versions 2.6.x up to 2.6.18
Description The issue allows local users to cause a denial of service, resulting in a crash, by utilizing a malformed file stream. This triggers a NULL pointer dereference in the superblock doinit function. The issue can be demonstrated using an HFS filesystem image when SELinux hooks are enabled.
Recommendations For Linux kernel versions 2.6.x up to 2.6.18, consider disabling SELinux hooks as a temporary workaround to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-6056
DSA-1304
RHSA-2007:0014
RHSA-2007_0014

Affected Products

Linux Kernel
Red Hat