kernel: IA32 System Call Entry Point Vulnerability
Published Sep 22, 2010
7.2
HIGHCVSS 2.0
EPSS 3.82%
Description
The IA32 system call emulation functionality in arch/x86/ia32/ia32entry.S in the Linux kernel before 2.6.36-rc4-git2 on the x86_64 platform does not zero extend the %eax register after the 32-bit entry path to ptrace is used, which allows local users to gain privileges by triggering an out-of-bounds access to the system call table using the %rax register. NOTE: this vulnerability exists because of a CVE-2007-4573 regression.
Affected products
No data.
Configuration 1
- < 2.6.36
- 2.6.36
- 2.6.36
- 2.6.36
- 2.6.36
Configuration 2
Configuration 3
- 9.10
- 10.04
- 10.10
No data.
Red Hat Enterprise Linux 6
kernel-0:2.6.32-71.7.1.el6
Fixed · RHSA-2010:0842
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 | kernel-0:2.6.32-71.7.1.el6 | Fixed | RHSA-2010:0842 |
No package ranges for this CVE.
Remediation
Red Hat statement
This issue did not affect the versions of Linux kernel as shipped with Red Hat Enterprise Linux 3, 4, 5, and Red Hat Enterprise MRG, as they do not contain the upstream commit d4d67150 that introduced this flaw. More information can be found in this kbase: https://access.redhat.com/kb/docs/DOC-40330
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
No CVSS v3.0 score for this CVE.
AV:L/AC:L/Au:N/C:C/I:C/A:C
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (14 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 3.82% (0.03818) | 89.73th | v5 (v2026.06.15) |
| Jun 15, 2026 | 3.82% (0.03818) | 88.66th | v5 (v2026.06.15) |
| May 15, 2026 | 7.23% (0.07235) | 91.70th | v4 (v2025.03.14) |
| Feb 13, 2026 | 6.17% (0.06169) | 90.62th | v4 (v2025.03.14) |
| Dec 16, 2025 | 4.73% (0.04727) | 89.01th | v4 (v2025.03.14) |
| Mar 30, 2025 | 5.76% (0.05762) | 89.54th | v4 (v2025.03.14) |
| Mar 29, 2025 | 4.68% (0.04683) | 81.85th | v4 (v2025.03.14) |
| Mar 24, 2025 | 5.76% (0.05762) | 89.55th | v4 (v2025.03.14) |
| Mar 17, 2025 | 7.19% (0.07187) | 90.93th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.04% (0.00042) | 0.34th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.04% (0.00042) | 0.50th | v3 (v2023.03.01) |
| Mar 6, 2023 | 3.22% (0.03220) | 84.21th | v2 (v2022.01.01) |
| Apr 1, 2022 | 3.22% (0.03220) | 82.61th | v2 (v2022.01.01) |
| Feb 4, 2022 | 3.22% (0.03220) | 65.30th | v2 (v2022.01.01) |
References (20)
- http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=36d001c70d8a0144ac1d038f6876c484849a74de x_refsource_CONFIRM
- http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=eefdca043e8391dcd719711716492063030b55ac x_refsource_CONFIRM
- http://lists.opensuse.org/opensuse-security-announce/2010-09/msg00006.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2011-02/msg00000.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://secunia.com/advisories/42758 third-party-advisoryx_refsource_SECUNIAThird Party Advisory
- http://sota.gen.nz/compat2/ x_refsource_MISCThird Party Advisory
- http://www.kernel.org/pub/linux/kernel/v2.6/snapshots/patch-2.6.36-rc4-git2.log x_refsource_CONFIRMBroken Link
- http://www.mandriva.com/security/advisories?name=MDVSA-2010:198 vendor-advisoryx_refsource_MANDRIVAThird Party Advisory
- http://www.mandriva.com/security/advisories?name=MDVSA-2010:247 vendor-advisoryx_refsource_MANDRIVAThird Party Advisory
- http://www.openwall.com/lists/oss-security/2010/09/16/1 mailing-listx_refsource_MLISTMailing ListPatchThird Party Advisory
- http://www.openwall.com/lists/oss-security/2010/09/16/3 mailing-listx_refsource_MLISTMailing ListPatchThird Party Advisory
- http://www.redhat.com/support/errata/RHSA-2010-0842.html vendor-advisoryx_refsource_REDHATThird Party Advisory
- http://www.ubuntu.com/usn/USN-1041-1 vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- http://www.vupen.com/english/advisories/2010/3117 vdb-entryx_refsource_VUPENThird Party Advisory
- http://www.vupen.com/english/advisories/2011/0070 vdb-entryx_refsource_VUPENThird Party Advisory
- http://www.vupen.com/english/advisories/2011/0298 vdb-entryx_refsource_VUPENThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2010-3301 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=634449 x_refsource_CONFIRMExploitIssue TrackingThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2010-3301
- https://www.cve.org/CVERecord?id=CVE-2010-3301
Change history (0)
No recorded changes yet.