Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2006-3468

36
FAUCET Score

CVE-2006-3468 describes a remote denial-of-service vulnerability affecting Linux kernel versions 2.6.x when using both NFS and EXT3. An unauthenticated remote attacker can trigger a file system panic and force an exported directory to remount read-only by sending a crafted UDP packet with a bad file handle during an NFS V2 lookup procedure. This vulnerability has a CVSS score of 7.8 (High), indicating a network-based attack with low complexity and a complete impact on availability. While not listed on the KEV catalog or Hot List, a public exploit (EDB-28358) exists, though there is no evidence of active exploitation or significant community discussion.

Impacted Technologies

VendorProductVersion(s)CPE
2.6.0CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:2.6.0:*:*:*:*:*:*:*
2.6.0CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:2.6.0:*:64-bit_x86:*:*:*:*:*
2.6.0CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:2.6.0:*:itanium_ia64_montecito:*:*:*:*:*
2.6.0CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:2.6.0:test1:*:*:*:*:*:*
2.6.0CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:2.6.0:test10:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 2.0

7.8HIGH

AV:N/AC:L/Au:N/C:N/I:N/A:C

Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
COMPLETE
Access Vector
NETWORK
Access Complexity
LOW
Authentication
NONE
Exploitability Score
10.0
Impact Score
6.9
CvssVersion
2.0

Exploit Intelligence

EPSS Score
15.69%
Probability of exploitation in next 30 days
EPSS Percentile
96.5%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
ExploitDB: EDB-28358 · Aug 7, 2006
This CVE's current EPSS score of 0.1569 is in the 95th percentile among its peer group of 51,553 CVEs.

Social Chatter

No social media mentions found for this CVE.

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (1)

redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 4Fixed in: kernel-0:2.6.9-42.0.2.EL
View patch

Vendor Advisories (1)

redhatCVE-2006-3468Important

security flaw

Jul 17, 2006

References

lkml.org / lkml/2006/7/17/41
bugzilla.redhat.com / bugzilla/show_bug.cgi
secunia.com / advisories/21369
secunia.com / advisories/21605
secunia.com / advisories/21614
secunia.com / advisories/21847
secunia.com / advisories/21934
secunia.com / advisories/22093
secunia.com / advisories/22148
secunia.com / advisories/22174
secunia.com / advisories/22822
oval.cisecurity.org / repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9809
support.avaya.com / elmodocs2/security/ASA-2006-203.htm
debian.org / security/2006/dsa-1184
mandriva.com / security/advisories
mandriva.com / security/advisories
novell.com / linux/security/advisories/2006_21_sr.html
novell.com / linux/security/advisories/2006_22_sr.html
novell.com / linux/security/advisories/2006_57_kernel.html
novell.com / linux/security/advisories/2006_64_kernel.html
redhat.com / support/errata/RHSA-2006-0617.html
securityfocus.com / bid/19396
trustix.org / errata/2006/0046
ubuntu.com / usn/usn-346-1