4.7
CVSSv2

CVE-2006-0039

Published: 19/05/2006 Updated: 13/02/2023
CVSS v2 Base Score: 4.7 | Impact Score: 7.8 | Exploitability Score: 1.9
VMScore: 418
Vector: AV:L/AC:H/Au:N/C:P/I:N/A:C

Vulnerability Summary

Race condition in the do_add_counters function in netfilter for Linux kernel 2.6.16 allows local users with CAP_NET_ADMIN capabilities to read kernel memory by triggering the race condition in a way that produces a size value that is inconsistent with allocated memory, which leads to a buffer over-read in IPT_ENTRY_ITERATE.

Vulnerable Product Search on Vulmon Subscribe to Product

linux linux kernel 2.6.16

Vendor Advisories

A race condition was discovered in the do_add_counters() functions Processes which do not run with full root privileges, but have the CAP_NET_ADMIN capability can exploit this to crash the machine or read a random piece of kernel memory In Ubuntu there are no packages that are affected by this, so this can only be an issue for you if you use thi ...
Several local and remote vulnerabilities have been discovered in the Linux kernel that may lead to a denial of service or the execution of arbitrary code The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2005-3359 Franz Filz discovered that some socket calls permit causing inconsistent reference count ...