CVE-2006-5173
published 2006-10-17CVE-2006-5173: Linux kernel does not properly save or restore EFLAGS during a context switch, or reset the flags when creating new threads, which allows local users to cause…
PriorityP48low2.1CVSS 2.0
AVLACLAuNCNINAP
EPSS
0.42%
34.8th percentile
Linux kernel does not properly save or restore EFLAGS during a context switch, or reset the flags when creating new threads, which allows local users to cause a denial of service (process crash), as demonstrated using a process that sets the Alignment Check flag (EFLAGS 0x40000), which triggers a SIGBUS in other processes that have an unaligned access.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| linux | linux_kernel | 2.4.0 – 2.6.19 | — |
CVSS provenance
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:N/I:N/A:P
vendor_ubuntu7.5HIGH
vendor_redhat2.1LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-pm7g-vxcv-89q8: Linux kernel does not properly save or restore EFLAGS during a context switch, or reset the flags when creating new threads, which allows local users
ghsa_unreviewed·2022-05-01
CVE-2006-5173 [LOW] GHSA-pm7g-vxcv-89q8: Linux kernel does not properly save or restore EFLAGS during a context switch, or reset the flags when creating new threads, which allows local users
Linux kernel does not properly save or restore EFLAGS during a context switch, or reset the flags when creating new threads, which allows local users to cause a denial of service (process crash), as demonstrated using a process that sets the Alignment Check flag (EFLAGS 0x40000), which triggers a SIGBUS in other processes that have an unaligned access.
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2006-12-14·CVSS 7.5
CVE-2006-5619 [HIGH] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Linux kernel vulnerabilities
Mark Dowd discovered that the netfilter iptables module did not
correcly handle fragmented packets. By sending specially crafted
packets, a remote attacker could exploit this to bypass firewall
rules. This has only be fixed for Ubuntu 6.10; the corresponding fix
for Ubuntu 5.10 and 6.06 will follow soon. (CVE-2006-4572)
Dmitriy Monakhov discovered an information leak in the
__block_prepare_write() function. During error recovery, this function
did not properly clear memory buffers which could allow local users to
read portions of unlinked files. This only affects Ubuntu 5.10.
(CVE-2006-4813)
ADLab Venustech Info Ltd discovered that the ATM network driver
referenced an already released pointer in some circumstance
Red Hat
CVE-2006-5173: Linux kernel does not properly save or restore EFLAGS during a context switch, or reset the flags when creating new threads, which allows local users
vendor_redhat·CVSS 2.1
CVE-2006-5173 [LOW] CVE-2006-5173: Linux kernel does not properly save or restore EFLAGS during a context switch, or reset the flags when creating new threads, which allows local users
Linux kernel does not properly save or restore EFLAGS during a context switch, or reset the flags when creating new threads, which allows local users to cause a denial of service (process crash), as demonstrated using a process that sets the Alignment Check flag (EFLAGS 0x40000), which triggers a SIGBUS in other processes that have an unaligned access.
Statement: Not Vulnerable. This flaw only affects kernel versions 2.6.14 to 2.6.18. Red Hat Enterprise Linux 2.1, 3, and 4 does not ship with a vulnerable kernel version.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://kernel.org/git/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=47a5c6fa0e204a2b63309c648bb2fde36836c826http://secunia.com/advisories/23361http://secunia.com/advisories/23384http://secunia.com/advisories/23474http://secunia.com/advisories/23593http://secunia.com/advisories/25691http://www.mandriva.com/security/advisories?name=MDKSA-2007:002http://www.novell.com/linux/security/advisories/2006_79_kernel.htmlhttp://www.securityfocus.com/archive/1/471457http://www.securityfocus.com/bid/21851http://www.ubuntu.com/usn/usn-395-1http://kernel.org/git/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=47a5c6fa0e204a2b63309c648bb2fde36836c826http://secunia.com/advisories/23361http://secunia.com/advisories/23384http://secunia.com/advisories/23474http://secunia.com/advisories/23593http://secunia.com/advisories/25691http://www.mandriva.com/security/advisories?name=MDKSA-2007:002http://www.novell.com/linux/security/advisories/2006_79_kernel.htmlhttp://www.securityfocus.com/archive/1/471457http://www.securityfocus.com/bid/21851http://www.ubuntu.com/usn/usn-395-1
2006-10-17
Published