PT-2006-7591 · Opensuse+2 · Opensuse+2
Published
1970-01-01
·
Updated
2018-10-30
·
CVE-2006-0744
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:C |
Name of the Vulnerable Software and Affected Versions
Linux kernel before 2.6.16.5
openSUSE (affected versions not specified)
Description
The issue is related to the Linux kernel and multiple packages in the openSUSE operating system. The Linux kernel does not properly handle uncanonical return addresses on Intel EM64T CPUs, which can cause the kernel exception handler to run on the user stack with the wrong GS. The openSUSE packages have multiple vulnerabilities that can lead to a breach of confidentiality, integrity, and availability of protected information. These vulnerabilities can be exploited remotely.
Recommendations
For Linux kernel before 2.6.16.5, update to a version 2.6.16.5 or later.
For openSUSE, since the affected versions are not specified, it is recommended to check the official openSUSE website for the latest security updates and apply them accordingly. Additionally, consider restricting access to the vulnerable packages until a patch is available.
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Linux Kernel
Red Hat
Opensuse