CVE-2006-2629 describes a race condition in Linux kernel versions 2.6.15 to 2.6.17 on Symmetric Multiprocessing (SMP) platforms. This flaw allows a local attacker to trigger a denial of service (system crash) by rapidly creating and exiting tasks while simultaneously accessing their /proc entries, leading to memory corruption. The vulnerability has a CVSS score of 4.0, indicating a low attack complexity (AC:H) but a high impact on availability (A:C), as it can cause a system crash. Authentication is not required (Au:N), but local access is necessary (AV:L). There is no evidence of active exploitation in the wild, and it is not listed on the KEV catalog or Hot List. While no Metasploit or Nuclei modules exist, an exploit demonstrating a local denial of service is available on ExploitDB. Community discussion and media coverage for this CVE are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.6.15CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:2.6.15:*:*:*:*:*:*:* | ||
2.6.15.1CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:2.6.15.1:*:*:*:*:*:*:* | ||
2.6.15.2CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:2.6.15.2:*:*:*:*:*:*:* | ||
2.6.15.3CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:2.6.15.3:*:*:*:*:*:*:* | ||
2.6.15.4CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:2.6.15.4:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:H/Au:N/C:N/I:N/A:C
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.