CVE-2010-3301 describes a privilege escalation vulnerability in the Linux kernel affecting x86_64 systems running versions prior to 2.6.36-rc4-git2. Specifically, the IA32 system call emulation functionality fails to zero-extend the %eax register, allowing local users to gain privileges through an out-of-bounds access to the system call table. This vulnerability is a regression of CVE-2007-4573 and impacts various Linux distributions including Canonical, SUSE, and general Linux kernels. With a CVSS score of 7.2 (High), this vulnerability has a low attack complexity and requires local access, but allows for complete compromise of confidentiality, integrity, and availability. The FAUCET Risk Score is 90/100, indicating a significant risk. While not actively exploited in the wild and not listed in CISA's KEV catalog, exploit code (EDB-15023) is publicly available on ExploitDB. Despite the availability of exploit code, there is minimal community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.6.36CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
2.6.36CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:2.6.36:-:*:*:*:*:*:* | ||
2.6.36CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:2.6.36:rc1:*:*:*:*:*:* | ||
2.6.36CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:2.6.36:rc2:*:*:*:*:*:* | ||
2.6.36CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:2.6.36:rc3:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:L/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.5 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.