CVE-2006-0039
MediumRace condition in the do_add_counters function in netfilter for Linux kernel 2.6.16 allows local users with CAP_NET_ADMIN capabilities to read kernel memory by triggering the race condition in a way that produces a size value that is inconsistent with allocated memory, which leads to a buffer over-read in IPT_ENTRY_ITERATE.
CVSS 2.0 score
4.7
AV:L/AC:H/Au:N/C:P/I:N/A:C
Weakness type
CWE-362CVE-2006-0039 is a Race Condition vulnerability
What is Race Condition?
The product contains a code sequence that can run concurrently with other code, creating unexpected states. Learn more on MITRE CWE
References
22 total-
Patch
-
-
-
-
Frequently asked questions
-
What is CVE-2006-0039?
CVE-2006-0039 is a Medium severity Linux kernel vulnerability with a CVSS score of 4.7 out of 10 , classified as a Race Condition flaw (CWE-362) . CVE-2006-0039 has not been confirmed as actively exploited and is not listed in the CISA KEV catalog.
-
What is the CVSS score for CVE-2006-0039?
CVE-2006-0039 has a CVSS score of 4.7 out of 10, rated Medium severity (CVSS 2.0). The vector string is
AV:L/AC:H/Au:N/C:P/I:N/A:C. -
Is there a patch available for CVE-2006-0039?
Monitor the NIST NVD and your Linux distribution's security advisories for CVE-2006-0039 patch availability.
-
Is CVE-2006-0039 actively exploited?
No. CVE-2006-0039 has not been confirmed as actively exploited. It is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.