CVE-2007-4573
The IA32 system call emulation functionality in Linux kernel 2.4.x and 2.6.x before 2.6.22.7, when running on the x86_64 architecture, does not zero extend the eax register after the 32bit entry path to ptrace is used, which might allow local users to…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.82%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The IA32 system call emulation functionality in Linux kernel 2.4.x and 2.6.x before 2.6.22.7, when running on the x86_64 architecture, does not zero extend the eax register after the 32bit entry path to ptrace is used, which might allow local users to gain privileges by triggering an out-of-bounds access to the system call table using the %RAX register.
- CVSS 2.0
- 7.2 HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
- EPSS
- 0.82% probability · 55th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- linux/linux kernel
- Source
- secalert@redhat.com
References
- http://fedoranews.org/updates/FEDORA-2007-229.shtml
- http://kernel.org/pub/linux/kernel/v2.4/ChangeLog-2.4.35.3
- http://lists.opensuse.org/opensuse-security-announce/2007-12/msg00001.html
- http://lkml.org/lkml/2007/9/21/512Patch
- http://lkml.org/lkml/2007/9/21/513
- http://marc.info/?l=full-disclosure&m=119062587407908&w=2
- http://secunia.com/advisories/26917
- http://secunia.com/advisories/26919
- http://secunia.com/advisories/26934
- http://secunia.com/advisories/26953
- http://secunia.com/advisories/26955
- http://secunia.com/advisories/26978
- http://secunia.com/advisories/26994
- http://secunia.com/advisories/26995
- http://secunia.com/advisories/27212
- http://secunia.com/advisories/27227
- http://secunia.com/advisories/27912
- http://secunia.com/advisories/29058
- http://securitytracker.com/id?1018748
- http://www.debian.org/security/2007/dsa-1378
- http://www.debian.org/security/2007/dsa-1381
- http://www.debian.org/security/2008/dsa-1504
- http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.22.7
- http://www.mandriva.com/security/advisories?name=MDKSA-2007:195
- http://www.mandriva.com/security/advisories?name=MDKSA-2007:196
- http://www.mandriva.com/security/advisories?name=MDVSA-2008:008
- http://www.mandriva.com/security/advisories?name=MDVSA-2008:105
- http://www.novell.com/linux/security/advisories/2007_53_kernel.html
- http://www.redhat.com/support/errata/RHSA-2007-0936.html
- http://www.redhat.com/support/errata/RHSA-2007-0937.html
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.