Back

CVE-2005-2459

The huft_build function in inflate.c in the zlib routines in the Linux kernel before 2.6.12.5 returns the wrong value, which allows remote attackers to cause a denial of service (kernel crash) via a certain compressed file that leads to a null pointer dereference, a different vulnerability than CVE-2005-2458.

Published: Aug 23, 2005 Modified: Jun 16, 2026
CWE-476

CVSS Metrics

Affected Products (64)

Vendor Product Version
linux linux_kernel 2.6.0
linux linux_kernel 2.6.0
linux linux_kernel 2.6.0
linux linux_kernel 2.6.0
linux linux_kernel 2.6.0
linux linux_kernel 2.6.0
linux linux_kernel 2.6.0
linux linux_kernel 2.6.0
linux linux_kernel 2.6.0
linux linux_kernel 2.6.0
linux linux_kernel 2.6.0
linux linux_kernel 2.6.0
linux linux_kernel 2.6.1
linux linux_kernel 2.6.1
linux linux_kernel 2.6.1
linux linux_kernel 2.6.2
linux linux_kernel 2.6.3
linux linux_kernel 2.6.4
linux linux_kernel 2.6.5
linux linux_kernel 2.6.6

…and 44 more

GitHub Security Advisory GHSA-g8ph-8hmr-373j

The huft_build function in inflate.c in the zlib routines in the Linux kernel before 2.6.12.5...

Risk Scores

CVSS Score 5.0 / 10
EPSS Score 4.63%

Top 9% most likely to be exploited

Threat Score 21.4 / 100

Data Sources

NVD EPSS GitHub