CVE-2007-3731

CVSS v2.0 4.9 (Medium)
49% Progress
EPSS 0.04 % (11th)
0.04% Progress
Affected Products 1
Advisories 2

The Linux kernel 2.6.20 and 2.6.21 does not properly handle an invalid LDT segment selector in %cs (the xcs field) during ptrace single-step operations, which allows local users to cause a denial of service (NULL dereference and OOPS) via certain code that makes ptrace PTRACE_SETREGS and PTRACE_SINGLESTEP requests, related to the TRACE_IRQS_ON function, and possibly related to the arch_ptrace function.

Weaknesses
CWE-20
Improper Input Validation
CVE Status
PUBLISHED
CNA
Red Hat, Inc.
Published Date
2007-09-17 17:17:00
(17 years ago)
Updated Date
2023-02-13 02:18:02
(19 months ago)

Affected Products

Loading...
Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Linux Kernel 2.6.20 cpe:2.3:o:linux:linux_kernel:2.6.20
  Linux Kernel 2.6.21 cpe:2.3:o:linux:linux_kernel:2.6.21
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...