Description
madvise_remove in Linux kernel 2.6.16 up to 2.6.16.6 does not follow file and mmap restrictions, which allows local users to bypass IPC permissions and replace portions of readonly tmpfs files with zeroes, aka the MADV_REMOVE vulnerability. NOTE: this description was originally written in a way that combined two separate issues. The mprotect issue now has a separate name, CVE-2006-2071.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-1097-1 | New Kernel 2.4.27 packages fix several vulnerabilities |
Debian DSA |
DSA-1103-1 | New Linux kernel 2.6.8 packages fix several vulnerabilities |
EUVD |
EUVD-2006-1528 | madvise_remove in Linux kernel 2.6.16 up to 2.6.16.6 does not follow file and mmap restrictions, which allows local users to bypass IPC permissions and replace portions of readonly tmpfs files with zeroes, aka the MADV_REMOVE vulnerability. NOTE: this description was originally written in a way that combined two separate issues. The mprotect issue now has a separate name, CVE-2006-2071. |
References
History
No history.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-07T17:12:22.161Z
Reserved: 2006-03-30T00:00:00.000Z
Link: CVE-2006-1524
No data.
Status : Modified
Published: 2006-04-19T18:18:00.000
Modified: 2026-04-16T00:27:16.627
Link: CVE-2006-1524
No data.
OpenCVE Enrichment
No data.
Weaknesses
Debian DSA
EUVD