VYPR
Unrated severityNVD Advisory· Published May 3, 2001· Updated Apr 16, 2026

CVE-2001-0268

CVE-2001-0268

Description

The i386_set_ldt system call in NetBSD 1.5 and earlier, and OpenBSD 2.8 and earlier, when the USER_LDT kernel option is enabled, does not validate a call gate target, which allows local users to gain root privileges by creating a segment call gate in the Local Descriptor Table (LDT) with a target that specifies an arbitrary kernel address.

Affected products

2
  • cpe:2.3:o:netbsd:netbsd:*:*:*:*:*:*:*:*
    Range: <=1.5
  • cpe:2.3:o:openbsd:openbsd:*:*:*:*:*:*:*:*
    Range: <=2.8

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

8

News mentions

0

No linked articles in our index yet.