CVE-2010-3301
The IA32 system call emulation functionality in arch/x86/ia32/ia32entry.S in the Linux kernel before 2.6.36-rc4-git2 on the x86_64 platform does not zero...
- Published
- Sep 22, 2010
- Updated
- Aug 7, 2024
- Assigning CNA
- redhat
- Evidence observed
- Sep 16, 2010
Primary CVSS
nvd · CVSS 2.0
AV:L/AC:L/Au:N/C:C/I:C/A:CLow · next 30 days
- Percentile
- 89.6%
- Model date
- Sep 21, 2026
EPSS is a statistical estimate, not a certainty or a measure of impact. Combine it with CVSS, KEV status, exposure and your environment.
Summary
The IA32 system call emulation functionality in arch/x86/ia32/ia32entry.S in the Linux kernel before 2.6.36-rc4-git2 on the x86_64 platform does not zero extend the %eax register after the 32-bit entry path to ptrace is used, which allows local users to gain privileges by triggering an out-of-bounds access to the system call table using the %rax register. NOTE: this vulnerability exists because of a CVE-2007-4573 regression.
Sources
3- LinuxEelvationExploit
Linux Eelvation(持续更新)
- linux-kernel-exploitsExploit
linux-kernel-exploits Linux平台提权漏洞集合
Responsible use
Use vulnerability information only on systems you own or are authorized to test. Kitploit links to public research metadata and does not store exploit code or malicious payloads.