CVE-2005-3257 describes a local privilege escalation vulnerability in the Linux kernel's VT implementation (vt_ioctl.c), affecting versions 2.6.12 and potentially 2.6.14.4. An unprivileged local user can exploit this by using the KDSKBSENT ioctl on another user's terminal to modify key bindings, thereby gaining elevated privileges. With a CVSS score of 4.6 (AV:L/AC:L/Au:N/C:P/I:P/A:P), this vulnerability has low attack complexity and requires local access, leading to potential confidentiality, integrity, and availability impacts. While not listed in CISA's KEV catalog and having no known Metasploit or Nuclei exploits, an ExploitDB entry (EDB-26353) exists, demonstrating a local command injection via console keymap manipulation. Community discussion and media coverage for this CVE are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.6.12CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:2.6.12:*:*:*:*:*:*:* | ||
2.6.14.4CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:2.6.14.4:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:L/Au:N/C:P/I:P/A:P
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.