CVE-2006-2444 EXPLOIT
7.8
HIGH · CVSS 2.0 · EPSS 22.1% (pctl 98)
Patch early
A public exploit exists.
Description
The snmp_trap_decode function in the SNMP NAT helper for Linux kernel before 2.6.16.18 allows remote attackers to cause a denial of service (crash) via unspecified remote attack vectors that cause failures in snmp_trap_decode that trigger (1) frees of random memory or (2) frees of previously-freed memory (double-free) by snmp_trap_decode as well as its calling function, as demonstrated via certain test cases of the PROTOS SNMP test suite.
Scoring
| CVSS | 7.8 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
| EPSS | 22.11% — more likely to be exploited than 98% of all CVEs |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2006-05-25 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| linux | linux kernel |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Linux Kernel < 2.6.16.18 - Netfilter NAT SNMP Module Remote Denial of Service | 2006-06-05 |
References
- http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.16.18
- http://secunia.com/advisories/20182
- http://secunia.com/advisories/20225
- http://secunia.com/advisories/20716
- http://secunia.com/advisories/21035
- http://secunia.com/advisories/21136
- http://secunia.com/advisories/21179
- http://secunia.com/advisories/21498
- http://secunia.com/advisories/21605
- http://secunia.com/advisories/21983
- http://secunia.com/advisories/22082
- http://secunia.com/advisories/22093
- http://secunia.com/advisories/22174
- http://secunia.com/advisories/22822
- http://securitytracker.com/id?1016153
- http://support.avaya.com/elmodocs2/security/ASA-2006-180.htm
- http://support.avaya.com/elmodocs2/security/ASA-2006-203.htm
- http://www.debian.org/security/2006/dsa-1183
- http://www.debian.org/security/2006/dsa-1184
- http://www.kb.cert.org/vuls/id/681569
→ the Explorer · watch your stack · NVD