← back
CVE-2010-3301

CVE-2010-3301

23Vexday Risk Score

No sign of exploitation. It has a public proof of concept.

ssvc Attendepss 3.8%
from disclosure to weapon0 days
Published on NVDSep 22
1st PoCSep 16
exploitation probability
3.8%top 11% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
The IA32 system call emulation functionality in arch/x86/ia32/ia32entry.S in the Linux kernel before 2.6.36-rc4-git2 on the x86_64 platform does not zero extend the %eax register after the 32-bit entry path to ptrace is used, which allows local users to gain privileges by triggering an out-of-bounds access to the system call table using the %rax register. NOTE: this vulnerability exists because of a CVE-2007-4573 regression.
Affected products
n/a · n/a
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.