First published: Tue Sep 19 2006(Updated: )
The Linux kernel 2.6.17.10 and 2.6.17.11 and 2.6.18-rc5 allows local users to cause a denial of service (crash) via an SCTP socket with a certain SO_LINGER value, possibly related to the patch for CVE-2006-3745. NOTE: older kernel versions for specific Linux distributions are also affected, due to backporting of the CVE-2006-3745 patch.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Linux Kernel | =2.6.17.10 | |
Linux Kernel | =2.6.17.11 | |
Linux Kernel | =2.6.18-rc5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-4535 is considered a denial of service vulnerability that can cause system crashes.
Local users running Linux kernel versions 2.6.17.10, 2.6.17.11, and 2.6.18-rc5 are affected by CVE-2006-4535.
To fix CVE-2006-4535, update your Linux kernel to a version that is not affected by this vulnerability.
CVE-2006-4535 involves a local denial of service attack through misuse of SCTP sockets.
Yes, older kernel versions for specific Linux distributions may also be affected by CVE-2006-4535.