PT-2010-4719 · Linux+1 · Linux Kernel+1

Ben Hawkes

·

Published

2010-09-22

·

Updated

2024-06-15

·

CVE-2010-3301

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 2.6.36-rc4-git2
Description The issue is related to the IA32 system call emulation functionality in the Linux kernel on the x86 64 platform. It does not properly zero extend the %eax register after using the 32-bit entry path to ptrace, allowing local users to gain privileges. This is achieved by triggering an out-of-bounds access to the system call table using the %rax register.
Recommendations For Linux kernel versions prior to 2.6.36-rc4-git2, update to version 2.6.36-rc4-git2 or later to resolve the issue.

Exploit

Fix

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2010-3301
OPENSUSE-SU-2024:10128-1
RHSA-2010:0842
RHSA-2010_0842

Affected Products

Linux Kernel
Red Hat