CVE Vulnerabilities

CVE-2006-1588

Published: Apr 03, 2006 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
2.1 LOW
AV:L/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

The bridge ioctl (if_bridge code) in NetBSD 1.6 through 3.0 does not clear sensitive memory before copying ioctl results to the requesting process, which allows local users to obtain portions of kernel memory.

Affected Software

NameVendorStart VersionEnd Version
NetbsdNetbsd1.6 (including)1.6 (including)
NetbsdNetbsd1.6-beta (including)1.6-beta (including)
NetbsdNetbsd1.6.1 (including)1.6.1 (including)
NetbsdNetbsd1.6.2 (including)1.6.2 (including)
NetbsdNetbsd2.0 (including)2.0 (including)
NetbsdNetbsd2.0.1 (including)2.0.1 (including)
NetbsdNetbsd2.0.2 (including)2.0.2 (including)
NetbsdNetbsd2.0.3 (including)2.0.3 (including)
NetbsdNetbsd2.1 (including)2.1 (including)
NetbsdNetbsd3.0 (including)3.0 (including)

References