CVE-2006-2444
Detail
Modified After Enrichment
This CVE record has been updated after NVD enrichment efforts were completed. Enrichment data supplied by the NVD may require amendment due to these changes.
Description
The snmp_trap_decode function in the SNMP NAT helper for Linux kernel before 2.6.16.18 allows remote attackers to cause a denial of service (crash) via unspecified remote attack vectors that cause failures in snmp_trap_decode that trigger (1) frees of random memory or (2) frees of previously-freed memory (double-free) by snmp_trap_decode as well as its calling function, as demonstrated via certain test cases of the PROTOS SNMP test suite.
Metrics
CVSS Version 4.0
CVSS Version 3.x
CVSS Version 2.0
NVD enrichment efforts reference publicly available information to associate
vector strings. CVSS information contributed by other sources is also
displayed.
CVSS 4.0 Severity and Vector Strings:
NVD assessment
not yet provided.
CVSS 3.x Severity and Vector Strings:
NVD assessment
not yet provided.
CVSS 2.0 Severity and Vector Strings:
Vector:
(AV:N/AC:L/Au:N/C:N/I:N/A:C)
Evaluator Solution
Successful exploitation requires that the "ip_nat_snmp_basic" module is loaded and that traffic NAT is enabled on port 161 or 162.
This vulnerability is addressed in the following product release:
Linux, Linux Kernel, 2.6.16.18
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving NIST webspace.
We have provided these links to other web sites because they
may have information that would be of interest to you. No
inferences should be drawn on account of other sites being
referenced, or not, from this page. There may be other web
sites that are more appropriate for your purpose. NIST does
not necessarily endorse the views expressed, or concur with
the facts presented on these sites. Further, NIST does not
endorse any commercial products that may be mentioned on
these sites. Please address comments about this page to [email protected] .
URL
Source(s)
Tag(s)
http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.16.18
CVE, Inc., Red Hat
Patch
http://secunia.com/advisories/20182
CVE, Inc., Red Hat
http://secunia.com/advisories/20225
CVE, Inc., Red Hat
Patch
Vendor Advisory
http://secunia.com/advisories/20716
CVE, Inc., Red Hat
http://secunia.com/advisories/21035
CVE, Inc., Red Hat
http://secunia.com/advisories/21136
CVE, Inc., Red Hat
http://secunia.com/advisories/21179
CVE, Inc., Red Hat
http://secunia.com/advisories/21498
CVE, Inc., Red Hat
http://secunia.com/advisories/21605
CVE, Inc., Red Hat
http://secunia.com/advisories/21983
CVE, Inc., Red Hat
http://secunia.com/advisories/22082
CVE, Inc., Red Hat
http://secunia.com/advisories/22093
CVE, Inc., Red Hat
http://secunia.com/advisories/22174
CVE, Inc., Red Hat
http://secunia.com/advisories/22822
CVE, Inc., Red Hat
http://securitytracker.com/id?1016153
CVE, Inc., Red Hat
http://support.avaya.com/elmodocs2/security/ASA-2006-180.htm
CVE, Inc., Red Hat
http://support.avaya.com/elmodocs2/security/ASA-2006-203.htm
CVE, Inc., Red Hat
http://www.debian.org/security/2006/dsa-1183
CVE, Inc., Red Hat
http://www.debian.org/security/2006/dsa-1184
CVE, Inc., Red Hat
http://www.kb.cert.org/vuls/id/681569
CVE, Inc., Red Hat
US Government Resource
http://www.kernel.org/git/?p=linux/kernel/git/stable/linux-2.6.16.y.git%3Ba=commit%3Bh=1db6b5a66e93ff125ab871d6b3f7363412cc87e8
CVE, Inc., Red Hat
http://www.mandriva.com/security/advisories?name=MDKSA-2006:087
CVE, Inc., Red Hat
http://www.novell.com/linux/security/advisories/2006_42_kernel.html
CVE, Inc., Red Hat
http://www.novell.com/linux/security/advisories/2006_47_kernel.html
CVE, Inc., Red Hat
http://www.novell.com/linux/security/advisories/2006_64_kernel.html
CVE, Inc., Red Hat
http://www.osvdb.org/25750
CVE, Inc., Red Hat
http://www.redhat.com/support/errata/RHSA-2006-0437.html
CVE, Inc., Red Hat
http://www.redhat.com/support/errata/RHSA-2006-0580.html
CVE, Inc., Red Hat
http://www.redhat.com/support/errata/RHSA-2006-0617.html
CVE, Inc., Red Hat
http://www.securityfocus.com/bid/18081
CVE, Inc., Red Hat
http://www.ubuntu.com/usn/usn-302-1
CVE, Inc., Red Hat
http://www.vupen.com/english/advisories/2006/1916
CVE, Inc., Red Hat
https://exchange.xforce.ibmcloud.com/vulnerabilities/26594
CVE, Inc., Red Hat
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11318
CVE, Inc., Red Hat
Weakness Enumeration
CWE-ID
CWE Name
Source
NVD-CWE-Other
Other
NIST  
Change History
9 change records found show changes
CVE Modified by Red Hat, Inc.
6/16/2026 6:25:01 PM
Action
Type
Old Value
New Value
Added
Affected
[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]
CVE Status Change
4/15/2026 8:27:16 PM
Action
Type
Old Value
New Value
CVE Modified by CVE
11/20/2024 7:11:20 PM
Action
Type
Old Value
New Value
Added
Reference
http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.16.18
Added
Reference
http://secunia.com/advisories/20182
Added
Reference
http://secunia.com/advisories/20225
Added
Reference
http://secunia.com/advisories/20716
Added
Reference
http://secunia.com/advisories/21035
Added
Reference
http://secunia.com/advisories/21136
Added
Reference
http://secunia.com/advisories/21179
Added
Reference
http://secunia.com/advisories/21498
Added
Reference
http://secunia.com/advisories/21605
Added
Reference
http://secunia.com/advisories/21983
Added
Reference
http://secunia.com/advisories/22082
Added
Reference
http://secunia.com/advisories/22093
Added
Reference
http://secunia.com/advisories/22174
Added
Reference
http://secunia.com/advisories/22822
Added
Reference
http://securitytracker.com/id?1016153
Added
Reference
http://support.avaya.com/elmodocs2/security/ASA-2006-180.htm
Added
Reference
http://support.avaya.com/elmodocs2/security/ASA-2006-203.htm
Added
Reference
http://www.debian.org/security/2006/dsa-1183
Added
Reference
http://www.debian.org/security/2006/dsa-1184
Added
Reference
http://www.kb.cert.org/vuls/id/681569
Added
Reference
http://www.kernel.org/git/?p=linux/kernel/git/stable/linux-2.6.16.y.git%3Ba=commit%3Bh=1db6b5a66e93ff125ab871d6b3f7363412cc87e8
Added
Reference
http://www.mandriva.com/security/advisories?name=MDKSA-2006:087
Added
Reference
http://www.novell.com/linux/security/advisories/2006_42_kernel.html
Added
Reference
http://www.novell.com/linux/security/advisories/2006_47_kernel.html
Added
Reference
http://www.novell.com/linux/security/advisories/2006_64_kernel.html
Added
Reference
http://www.osvdb.org/25750
Added
Reference
http://www.redhat.com/support/errata/RHSA-2006-0437.html
Added
Reference
http://www.redhat.com/support/errata/RHSA-2006-0580.html
Added
Reference
http://www.redhat.com/support/errata/RHSA-2006-0617.html
Added
Reference
http://www.securityfocus.com/bid/18081
Added
Reference
http://www.ubuntu.com/usn/usn-302-1
Added
Reference
http://www.vupen.com/english/advisories/2006/1916
Added
Reference
https://exchange.xforce.ibmcloud.com/vulnerabilities/26594
Added
Reference
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11318
CVE Modified by Red Hat, Inc.
5/13/2024 9:36:48 PM
Action
Type
Old Value
New Value
CVE Modified by Red Hat, Inc.
2/12/2023 9:16:30 PM
Action
Type
Old Value
New Value
Added
Reference
http://www.kernel.org/git/?p=linux/kernel/git/stable/linux-2.6.16.y.git%3Ba=commit%3Bh=1db6b5a66e93ff125ab871d6b3f7363412cc87e8 [No Types Assigned]
Removed
Reference
http://www.kernel.org/git/?p=linux/kernel/git/stable/linux-2.6.16.y.git;a=commit;h=1db6b5a66e93ff125ab871d6b3f7363412cc87e8 [Patch]
CPE Deprecation Remap by NIST
10/30/2018 12:26:20 PM
Action
Type
Old Value
New Value
Changed
CPE Configuration
OR
*cpe:2.3:o:linux:linux_kernel:2.6.9:final:*:*:*:*:*:*
OR
*cpe:2.3:o:linux:linux_kernel:2.6.9:*:*:*:*:*:*:*
CVE Modified by Red Hat, Inc.
10/10/2017 9:30:55 PM
Action
Type
Old Value
New Value
Added
Reference
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11318 [No Types Assigned]
Removed
Reference
http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11318 [No Types Assigned]
CVE Modified by Red Hat, Inc.
7/19/2017 9:31:28 PM
Action
Type
Old Value
New Value
Added
Reference
https://exchange.xforce.ibmcloud.com/vulnerabilities/26594 [No Types Assigned]
Removed
Reference
http://xforce.iss.net/xforce/xfdb/26594 [No Types Assigned]
Initial CVE Analysis
5/25/2006 9:50:00 AM
Action
Type
Old Value
New Value
Quick Info
CVE Dictionary Entry: CVE-2006-2444 NVD
Published Date: 05/25/2006 NVD
Last Modified: 06/16/2026
Source: Red Hat, Inc.