CVE-2010-3301: High severity linux kernel vulnerability
Description of problem: CVE-2007-4573 regression
Reintroduced in v2.6.27-rc1 via commit d4d67150.
Upstream commits: http://git.kernel.org/linus/36d001c70d8a0144ac1d038f6876c484849a74de http://git.kernel.org/linus/eefdca043e8391dcd719711716492063030b55ac
References: http://sota.gen.nz/compat2/
Acknowledgements:
Red Hat would like to thank Ben Hawkes for reporting this issue.
Other sources
The IA32 system call emulation functionality in arch/x86/ia32/ia32entry.S in the Linux kernel before 2.6.36-rc4-git2 on the x8664 platform does not zero extend the %eax register after the 32-bit entry path to ptrace is used, which allows local users to gain privileges by triggering an out-of-bounds access to the system call table using the %rax register. NOTE: this vulnerability exists because of a CVE-2007-4573 regression.
— Debian
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2010-3301?
CVE-2010-3301 is considered a medium severity vulnerability that may lead to system instability.
How do I fix CVE-2010-3301?
To fix CVE-2010-3301, you should upgrade your Linux kernel to version 2.6.36 or later.
What versions of the Linux kernel are affected by CVE-2010-3301?
CVE-2010-3301 affects Linux kernel versions prior to 2.6.36.
Is there a known workaround for CVE-2010-3301?
Currently, there are no known workarounds for CVE-2010-3301 other than upgrading the kernel.
What applications or systems are impacted by CVE-2010-3301?
CVE-2010-3301 impacts systems running affected versions of the Linux kernel, including distributions like Ubuntu and SUSE.