Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2007-6206

12
FAUCET Score

CVE-2007-6206 describes a sensitive information disclosure vulnerability in the Linux kernel's do_coredump function (fs/exec.c), affecting versions 2.4.x and 2.6.x up to 2.6.24-rc3, including distributions like Canonical, Debian, and Red Hat. The flaw allows local users to potentially access sensitive data if a core dump file pre-exists and a root process subsequently creates a core dump in the same location without changing the file's UID. This vulnerability has a low severity, rated with a CVSS score of 2.1 (AV:L/AC:L/Au:N/C:P/I:N/A:N), indicating local access is required, and its primary impact is limited to confidentiality. The EPSS score is very low, suggesting a minimal likelihood of exploitation. There is no evidence of active exploitation, and no public exploit code exists on platforms like Metasploit or ExploitDB. The CVE has received no community discussion or media coverage, further indicating a lack of widespread attention or exploitation.

Impacted Technologies

VendorProductVersion(s)CPE
>= 2.4.0, <= 2.4.35.2CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 2.6.0, < 2.6.24CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
2.6.24CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:2.6.24:-:*:*:*:*:*:*
2.6.24CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:2.6.24:rc1:*:*:*:*:*:*
2.6.24CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:2.6.24:rc2:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 2.0

2.1LOW

AV:L/AC:L/Au:N/C:P/I:N/A:N

Confidentiality Impact
PARTIAL
Integrity Impact
NONE
Availability Impact
NONE
Access Vector
LOCAL
Access Complexity
LOW
Authentication
NONE
Exploitability Score
3.9
Impact Score
2.9
CvssVersion
2.0

Exploit Intelligence

EPSS Score
0.43%
Probability of exploitation in next 30 days
EPSS Percentile
34.8%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0043 is in the 63rd percentile among its peer group of 2,096 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.6 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (5)

redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 2.1Fixed in: kernel-0:2.4.18-e.67
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 2.1Fixed in: kernel-0:2.4.9-e.74
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 3Fixed in: kernel-0:2.4.21-57.EL
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 4Fixed in: kernel-0:2.6.9-67.0.4.EL
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 5Fixed in: kernel-0:2.6.18-53.1.6.el5
View patch

Vendor Advisories (1)

redhatCVE-2007-6206Moderate

Issue with core dump owner

Jul 10, 2004

References

bugzilla.kernel.org / show_bug.cgi
Issue TrackingVendor Advisory
git.kernel.org
lists.opensuse.org / opensuse-security-announce/2008-02/msg00005.html
Mailing ListThird Party Advisory
lists.opensuse.org / opensuse-security-announce/2008-06/msg00006.html
Mailing ListThird Party Advisory
lists.opensuse.org / opensuse-security-announce/2008-07/msg00002.html
Mailing ListThird Party Advisory
lists.vmware.com / pipermail/security-announce/2008/000023.html
Mailing ListThird Party Advisory
rhn.redhat.com / errata/RHSA-2008-0055.html
Third Party Advisory
secunia.com / advisories/27908
Third Party Advisory
secunia.com / advisories/28141
Third Party Advisory
secunia.com / advisories/28643
Third Party Advisory
secunia.com / advisories/28706
Third Party Advisory
secunia.com / advisories/28748
Third Party Advisory
secunia.com / advisories/28826
Third Party Advisory
secunia.com / advisories/28889
Third Party Advisory
secunia.com / advisories/28971
Third Party Advisory
secunia.com / advisories/29058
Third Party Advisory
secunia.com / advisories/30110
Third Party Advisory
secunia.com / advisories/30818
Third Party Advisory
secunia.com / advisories/30962
Third Party Advisory
secunia.com / advisories/31246
Third Party Advisory
secunia.com / advisories/33280
Third Party Advisory
exchange.xforce.ibmcloud.com / vulnerabilities/38841
Third Party AdvisoryVDB Entry
oval.cisecurity.org / repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10719
Third Party Advisory
wiki.rpath.com / wiki/Advisories:rPSA-2008-0048
Broken Link
debian.org / security/2007/dsa-1436
Third Party Advisory
debian.org / security/2008/dsa-1503
Third Party Advisory
debian.org / security/2008/dsa-1504
Third Party Advisory
mandriva.com / security/advisories
Third Party Advisory
mandriva.com / security/advisories
Third Party Advisory
mandriva.com / security/advisories
Third Party Advisory
redhat.com / support/errata/RHSA-2008-0089.html
Third Party Advisory
redhat.com / support/errata/RHSA-2008-0211.html
Third Party Advisory
redhat.com / support/errata/RHSA-2008-0787.html
Third Party Advisory
securityfocus.com / archive/1/487808/100/0/threaded
Third Party AdvisoryVDB Entry
securityfocus.com / bid/26701
Third Party AdvisoryVDB Entry
ubuntu.com / usn/usn-574-1
Third Party Advisory
ubuntu.com / usn/usn-578-1
Third Party Advisory
vupen.com / english/advisories/2007/4090
Third Party Advisory
vupen.com / english/advisories/2008/2222/references
Third Party Advisory