CVE-2006-1056 describes a vulnerability in the Linux kernel (before 2.6.16.9) and FreeBSD kernel when running on specific AMD64 processors. It allows a local attacker to infer portions of floating-point instruction states from other processes due to incomplete saving/restoring of x87 registers, potentially leading to the leakage of sensitive information like cryptographic keys. The vulnerability has a low severity CVSS score of 2.1 (AV:L/AC:L/Au:N/C:P/I:N/A:N), indicating local access, low attack complexity, and a potential for partial confidentiality impact. It is categorized under CWE-310 (Cryptographic Issues). There is no evidence of active exploitation, and no public exploit code is available in Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage for this CVE are minimal, suggesting a lack of widespread attention or exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:o:freebsd:freebsd:*:*:*:*:*:*:*:* | ||
<= 2.6.16.8CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
2.6.0CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:2.6.0:*:*:*:*:*:*:* | ||
2.6.0CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:2.6.0:test1:*:*:*:*:*:* | ||
2.6.0CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:2.6.0:test10:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:L/Au:N/C:P/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.6 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.