---
title: "CVE-2006-1524\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2006-1524?format=md
keywords: index, follow
---

# CVE-2006-1524

Publication date 19 April 2006

Last updated 17 July 2025

---

Ubuntu priority

**Medium**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

Toggle side navigation

## Description

madvise\_remove in Linux kernel 2.6.16 up to 2.6.16.6 does not follow file
and mmap restrictions, which allows local users to bypass IPC permissions
and replace portions of readonly tmpfs files with zeroes, aka the
MADV\_REMOVE vulnerability. NOTE: this description was originally written
in a way that combined two separate issues. The mprotect issue now has a
separate name, CVE-2006-2071.

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| linux-source-2.6.15 | 7.04 feisty | Not in release |
| 6.10 edgy | Not in release |
| 6.06 LTS dapper | Not affected |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1524)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2006-1524)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2006-1524)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2006-1524)

### Other references

* <https://www.cve.org/CVERecord?id=CVE-2006-1524>
