Candidate: CVE-2006-3741 References: http://www.kernel.org/git/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=b8444d00762703e1b6146fce12ce2684885f8bf6 Description: The perfmonctl system call (sys_perfmonctl) in Linux kernel 2.4.x and 2.6 before 2.6.18, when running on Itanium systems, does not properly track the reference count for file descriptors, which allows local users to cause a denial of service (file descriptor consumption). Ubuntu-Description: Notes: dannf> I don't think 2.4 is affected - there are no existing calls to fput Bugs: upstream: released (2.6.18) linux-2.6: released (2.6.18-1) 2.6.8-sarge-security: released (2.6.8-16sarge6) [perfmon-fd-refcnt.dpatch] 2.4.27-sarge-security: N/A 2.6.10-hoary-security: ignored 2.6.12-breezy-security: ignored 2.6.15-dapper-security: ignored 2.6.17-edgy: released (2.6.17-10.31)