CVE-2007-4573
The IA32 system call emulation functionality in Linux kernel 2.4.x and 2.6.x before 2.6.22.7, when running on the x86_64 architecture, does not zero extend...
- Published
- Sep 24, 2007
- Updated
- Aug 7, 2024
- Assigning CNA
- redhat
- Evidence observed
- Sep 21, 2007
Primary CVSS
nvd · CVSS 2.0
AV:L/AC:L/Au:N/C:C/I:C/A:CLow · next 30 days
- Percentile
- 55.3%
- Model date
- Sep 21, 2026
EPSS is a statistical estimate, not a certainty or a measure of impact. Combine it with CVSS, KEV status, exposure and your environment.
Summary
The IA32 system call emulation functionality in Linux kernel 2.4.x and 2.6.x before 2.6.22.7, when running on the x86_64 architecture, does not zero extend the eax register after the 32bit entry path to ptrace is used, which might allow local users to gain privileges by triggering an out-of-bounds access to the system call table using the %RAX register.
Sources
2Robert Swiecki · linux_x86-64 · Sep 27, 2007
Wojciech Purczynski · linux · Sep 21, 2007
Responsible use
Use vulnerability information only on systems you own or are authorized to test. Kitploit links to public research metadata and does not store exploit code or malicious payloads.