CVE Vulnerabilities

CVE-2007-1000

Published: Mar 12, 2007 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.2 HIGH
AV:L/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

The ipv6_getsockopt_sticky function in net/ipv6/ipv6_sockglue.c in the Linux kernel before 2.6.20.2 allows local users to read arbitrary kernel memory via certain getsockopt calls that trigger a NULL dereference.

Affected Software

NameVendorStart VersionEnd Version
Linux_kernelLinux*2.6.20.1 (including)
Red Hat Enterprise Linux 5RedHatkernel-0:2.6.18-8.1.3.el5*
Linux-source-2.6.15Ubuntudapper*
Linux-source-2.6.17Ubuntuedgy*
Linux-source-2.6.20Ubuntufeisty*

References