CVE-2006-5753Incorrect Conversion between Numeric Types in Kernel

Severity
7.2HIGHNVD
EPSS
0.1%
top 70.00%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 30
Latest updateMay 1

Description

Unspecified vulnerability in the listxattr system call in Linux kernel, when a "bad inode" is present, allows local users to cause a denial of service (data corruption) and possibly gain privileges via unknown vectors.

CVSS vector

AV:L/AC:L/C:C/I:C/A:CExploitability: 3.9 | Impact: 10.0

Affected Packages2 packages

Also affects: Enterprise Linux 4.0

🔴Vulnerability Details

1
GHSA
GHSA-p2rv-pwrw-64p2: Unspecified vulnerability in the listxattr system call in Linux kernel, when a "bad inode" is present, allows local users to cause a denial of service2022-05-01

📋Vendor Advisories

2
Ubuntu
Linux kernel vulnerabilities2007-02-10
Red Hat
kernel listxattr syscall can corrupt user space programs2007-01-03

💬Community

2
Bugzilla
CVE-2006-5753 kernel listxattr syscall can corrupt user space programs2007-09-26
Bugzilla
CVE-2006-5753 listxattr syscall can corrupt user space programs [rhel-4.4]2006-12-22