Description
The IA32 system call emulation functionality in Linux kernel 2.4.x and 2.6.x before 2.6.22.7, when running on the x86_64 architecture, does not zero extend the eax register after the 32bit entry path to ptrace is used, which might allow local users to gain privileges by triggering an out-of-bounds access to the system call table using the %RAX register.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-1378-1 | New Linux 2.6.18 packages fix several vulnerabilities |
Debian DSA |
DSA-1378-2 | New Linux 2.6.18 packages fix several vulnerabilities |
Debian DSA |
DSA-1381-1 | New Linux 2.6.18 packages fix several vulnerabilities |
Debian DSA |
DSA-1381-2 | New Linux 2.6.18 packages fix several vulnerabilities |
Debian DSA |
DSA-1504-1 | New Linux kernel 2.6.8 packages fix several issues |
EUVD |
EUVD-2007-4555 | The IA32 system call emulation functionality in Linux kernel 2.4.x and 2.6.x before 2.6.22.7, when running on the x86_64 architecture, does not zero extend the eax register after the 32bit entry path to ptrace is used, which might allow local users to gain privileges by triggering an out-of-bounds access to the system call table using the %RAX register. |
Ubuntu USN |
USN-518-1 | linux-source-2.6.15, linux-source-2.6.17, linux-source-2.6.20 vulnerabilities |
References
History
No history.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-07T15:01:09.784Z
Reserved: 2007-08-28T00:00:00.000Z
Link: CVE-2007-4573
No data.
Status : Modified
Published: 2007-09-24T22:17:00.000
Modified: 2026-04-23T00:35:47.467
Link: CVE-2007-4573
OpenCVE Enrichment
No data.
Weaknesses
Debian DSA
EUVD
Ubuntu USN