CVE Vulnerabilities

CVE-2005-2617

Published: Aug 17, 2005 | Modified: Nov 07, 2023
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
3.6 LOW
AV:L/AC:L/Au:N/C:N/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
UNTRIAGED

The syscall32_setup_pages function in syscall32.c for Linux kernel 2.6.12 and later, on the 64-bit x86 platform, does not check the return value of the insert_vm_struct function, which allows local users to trigger a memory leak via a 32-bit application with crafted ELF headers.

Affected Software

Name Vendor Start Version End Version
Linux_kernel Linux 2.6.12-rc1 (including) 2.6.12-rc1 (including)
Linux_kernel Linux 2.6.12-rc4 (including) 2.6.12-rc4 (including)
Linux-source-2.6.15 Ubuntu dapper *
Linux-source-2.6.17 Ubuntu edgy *

References