MEDIUM · 5.6

CVE-2006-2448

Linux kernel before 2.6.16.21 and 2.6.17, when running on PowerPC, does not perform certain required access_ok checks, which allows local users to read arbitrary kernel memory on 64-bit systems (signa...

Vulnerability Description

Linux kernel before 2.6.16.21 and 2.6.17, when running on PowerPC, does not perform certain required access_ok checks, which allows local users to read arbitrary kernel memory on 64-bit systems (signal_64.c) and cause a denial of service (crash) and possibly read kernel memory on 32-bit systems (signal_32.c).

CVSS Score

5.6

MEDIUM

AV:L/AC:H/Au:N/C:C/I:N/A:C
Confidentiality
COMPLETE
Integrity
NONE
Availability
COMPLETE

Affected Products

VendorProductVersions
LinuxLinux Kernel2.6.0

References

FAQ

What is CVE-2006-2448?

CVE-2006-2448 is a vulnerability with a CVSS score of 5.6 (MEDIUM). Linux kernel before 2.6.16.21 and 2.6.17, when running on PowerPC, does not perform certain required access_ok checks, which allows local users to read arbitrary kernel memory on 64-bit systems (signa...

How severe is CVE-2006-2448?

CVE-2006-2448 has been rated MEDIUM with a CVSS base score of 5.6/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2006-2448?

Check the references section above for vendor advisories and patch information. Affected products include: Linux Linux Kernel.