CVE-2007-0771
published 2007-05-02CVE-2007-0771: The utrace support in Linux kernel 2.6.18, and other versions, allows local users to cause a denial of service (system hang) related to "MT exec +…
PriorityP410medium4.9CVSS 2.0
AVLACLAuNCNINAC
EPSS
0.38%
30.2th percentile
The utrace support in Linux kernel 2.6.18, and other versions, allows local users to cause a denial of service (system hang) related to "MT exec + utrace_attach spin failure mode," as demonstrated by ptrace-thrash.c.
Affected
126 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
CVSS provenance
nvdv2.04.9MEDIUMAV:L/AC:L/Au:N/C:N/I:N/A:C
vendor_redhat4.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kernel: ptrace: Crash on PTRACE_{ATTACH,DETACH} race
vendor_redhat·2008-04-02·CVSS 4.9
CVE-2008-2365 [MEDIUM] kernel: ptrace: Crash on PTRACE_{ATTACH,DETACH} race
kernel: ptrace: Crash on PTRACE_{ATTACH,DETACH} race
Race condition in the ptrace and utrace support in the Linux kernel 2.6.9 through 2.6.25, as used in Red Hat Enterprise Linux (RHEL) 4, allows local users to cause a denial of service (oops) via a long series of PTRACE_ATTACH ptrace calls to another user's process that trigger a conflict between utrace_detach and report_quiescent, related to "late ptrace_may_attach() check" and "race around &dead_engine_ops setting," a different vulnerability than CVE-2007-0771 and CVE-2008-1514. NOTE: this issue might only affect kernel versions before 2.6.16.x.
Red Hat
Tracing execution of a threaded executable causes kernel BUG report
vendor_redhat·2007-02-12·CVSS 4.9
CVE-2007-0771 [MEDIUM] Tracing execution of a threaded executable causes kernel BUG report
Tracing execution of a threaded executable causes kernel BUG report
The utrace support in Linux kernel 2.6.18, and other versions, allows local users to cause a denial of service (system hang) related to "MT exec + utrace_attach spin failure mode," as demonstrated by ptrace-thrash.c.
GHSA
GHSA-64w9-gfhc-7qwj: The utrace support in Linux kernel 2
ghsa_unreviewed·2022-05-01
CVE-2007-0771 [MEDIUM] GHSA-64w9-gfhc-7qwj: The utrace support in Linux kernel 2
The utrace support in Linux kernel 2.6.18, and other versions, allows local users to cause a denial of service (system hang) related to "MT exec + utrace_attach spin failure mode," as demonstrated by ptrace-thrash.c.
GHSA
GHSA-rv47-5vwq-v454: Race condition in the ptrace and utrace support in the Linux kernel 2
ghsa_unreviewed·2022-05-01·CVSS 4.9
CVE-2008-2365 [MEDIUM] CWE-362 GHSA-rv47-5vwq-v454: Race condition in the ptrace and utrace support in the Linux kernel 2
Race condition in the ptrace and utrace support in the Linux kernel 2.6.9 through 2.6.25, as used in Red Hat Enterprise Linux (RHEL) 4, allows local users to cause a denial of service (oops) via a long series of PTRACE_ATTACH ptrace calls to another user's process that trigger a conflict between utrace_detach and report_quiescent, related to "late ptrace_may_attach() check" and "race around &dead_engine_ops setting," a different vulnerability than CVE-2007-0771 and CVE-2008-1514. NOTE: this issue might only affect kernel versions before 2.6.16.x.
No detection rules found.
No public exploits indexed.
http://osvdb.org/35927http://secunia.com/advisories/25080http://securitytracker.com/id?1017979http://www.redhat.com/support/errata/RHSA-2007-0169.htmlhttp://www.securityfocus.com/bid/23720https://bugzilla.redhat.com/show_bug.cgi?id=227952https://bugzilla.redhat.com/show_bug.cgi?id=228816https://exchange.xforce.ibmcloud.com/vulnerabilities/34128https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9447http://osvdb.org/35927http://secunia.com/advisories/25080http://securitytracker.com/id?1017979http://www.redhat.com/support/errata/RHSA-2007-0169.htmlhttp://www.securityfocus.com/bid/23720https://bugzilla.redhat.com/show_bug.cgi?id=227952https://bugzilla.redhat.com/show_bug.cgi?id=228816https://exchange.xforce.ibmcloud.com/vulnerabilities/34128https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9447
2007-05-02
Published