CVE-2007-4573

Severity CVSS v4.0:
Pending analysis
Type:
CWE-264 Permissions, Privileges, and Access Control
Publication date:
24/09/2007
Last modified:
09/04/2025

Description

The IA32 system call emulation functionality in Linux kernel 2.4.x and 2.6.x before 2.6.22.7, when running on the x86_64 architecture, does not zero extend the eax register after the 32bit entry path to ptrace is used, which might allow local users to gain privileges by triggering an out-of-bounds access to the system call table using the %RAX register.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:linux:linux_kernel:*:*:x86_64:*:*:*:*:* 2.4.35 (including)
cpe:2.3:o:linux:linux_kernel:*:*:x86_64:*:*:*:*:* 2.6.22.6 (including)


References to Advisories, Solutions, and Tools