CVE-2005-2555 describes a privilege escalation vulnerability in Linux kernel versions 2.6.x, specifically affecting Debian and other Linux distributions. It allows local users with CAP_NET_ADMIN capabilities to perform unauthorized actions by manipulating socket policy access through ipv4/ip_sockglue.c and ipv6/ipv6_sockglue.c. The vulnerability has a CVSS score of 4.6 (medium severity), indicating a local attack vector with low complexity, potentially leading to partial confidentiality, integrity, and availability impacts. There is no evidence of active exploitation, nor are there public exploits available in Metasploit or ExploitDB, despite some community discussion and limited media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
3.1CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:3.1:*:*:*:*:*:*:* | ||
2.6.0CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:2.6.0:*:*:*:*:*:*:* | ||
2.6.0CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:2.6.0:test1:*:*:*:*:*:* | ||
2.6.0CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:2.6.0:test10:*:*:*:*:*:* | ||
2.6.0CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:2.6.0:test11:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:L/Au:N/C:P/I:P/A:P
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.