---
title: "CVE-2007-3731\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2007-3731?format=md
keywords: index, follow
---

# CVE-2007-3731

Publication date 17 September 2007

Last updated 24 July 2024

---

Ubuntu priority

**Low**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

Toggle side navigation

## Description

The Linux kernel 2.6.20 and 2.6.21 does not properly handle an invalid LDT
segment selector in %cs (the xcs field) during ptrace single-step
operations, which allows local users to cause a denial of service (NULL
dereference and OOPS) via certain code that makes ptrace PTRACE\_SETREGS and
PTRACE\_SINGLESTEP requests, related to the TRACE\_IRQS\_ON function, and
possibly related to the arch\_ptrace function.

### From the Ubuntu Security Team

Evan Teran discovered that the Linux kernel ptrace routines did not correctly
handle certain requests robustly. Local attackers could exploit this to crash
the system, causing a denial of service

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| linux-source-2.6.15 | 6.06 LTS dapper | Fixed 2.6.15-29.60 |
| linux-source-2.6.17 | 6.10 edgy | Fixed 2.6.17.1-12.41 |
| linux-source-2.6.20 | 7.04 feisty | Fixed 2.6.20-16.32 |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3731)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2007-3731)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2007-3731)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2007-3731)

### Related Ubuntu Security Notices (USN)

+ [USN-518-1](https://usn.ubuntu.com/USN-518-1)
+ linux-source-2.6.15, linux-source-2.6.17, linux-source-2.6.20 vulnerabilities
+ 25 September 2007

### Other references

* <https://www.cve.org/CVERecord?id=CVE-2007-3731>
