Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2005-2617


Vulnerability Score 3.6 3.6
CVE Id CVE-2005-2617
Last Modified 05 Sep 2008 04:52:14
Published 17 Aug 2005 12:00:00
Confidentiality Impact NONE NONE
Integrity Impact PARTIAL PARTIAL
Availability Impact PARTIAL PARTIAL
Access Vector LOCAL
Access Complexity LOW
Authentication NONE



The syscall32_setup_pages function in syscall32.c for Linux kernel 2.6.12 and later, on the 64-bit x86 platform, does not check the return value of the insert_vm_struct function, which allows local users to trigger a memory leak via a 32-bit application with crafted ELF headers.

Vulnerable Systems

Operating System

  • Linux Kernel 2.6.12


CONFIRM -;a=commit;h=9fb1759a3102c26cd8f64254a7c3e532782c2bb8

Last Updated: 27 May 2016 10:40:34