4.9
CVSSv2

CVE-2007-3731

Published: 17/09/2007 Updated: 13/02/2023
CVSS v2 Base Score: 4.9 | Impact Score: 6.9 | Exploitability Score: 3.9
VMScore: 437
Vector: AV:L/AC:L/Au:N/C:N/I:N/A:C

Vulnerability Summary

The Linux kernel 2.6.20 and 2.6.21 does not properly handle an invalid LDT segment selector in %cs (the xcs field) during ptrace single-step operations, which allows local users to cause a denial of service (NULL dereference and OOPS) via certain code that makes ptrace PTRACE_SETREGS and PTRACE_SINGLESTEP requests, related to the TRACE_IRQS_ON function, and possibly related to the arch_ptrace function.

Vulnerable Product Search on Vulmon Subscribe to Product

linux linux kernel 2.6.21

linux linux kernel 2.6.20

Vendor Advisories

Evan Teran discovered that the Linux kernel ptrace routines did not correctly handle certain requests robustly Local attackers could exploit this to crash the system, causing a denial of service (CVE-2007-3731) ...
Several local and remote vulnerabilities have been discovered in the Linux kernel that may lead to a denial of service or the execution of arbitrary code The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2007-3731 Evan Teran discovered a potential local denial of service (oops) in the handling of PTRA ...