The kernel in NetBSD, probably 5.0.1 and earlier, on x86 platforms does not properly handle a pre-commit failure of the iret instruction, which might allow local users to gain privileges via vectors related to a tempEIP pseudocode variable that is outside of the code-segment limits.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Netbsd | Netbsd | * | 5.0.1 (including) |
Netbsd | Netbsd | 0.8 (including) | 0.8 (including) |
Netbsd | Netbsd | 0.9 (including) | 0.9 (including) |
Netbsd | Netbsd | 1.0 (including) | 1.0 (including) |
Netbsd | Netbsd | 1.1 (including) | 1.1 (including) |
Netbsd | Netbsd | 1.2 (including) | 1.2 (including) |
Netbsd | Netbsd | 1.2.1 (including) | 1.2.1 (including) |
Netbsd | Netbsd | 1.3 (including) | 1.3 (including) |
Netbsd | Netbsd | 1.3.1 (including) | 1.3.1 (including) |
Netbsd | Netbsd | 1.3.2 (including) | 1.3.2 (including) |
Netbsd | Netbsd | 1.3.3 (including) | 1.3.3 (including) |
Netbsd | Netbsd | 1.5 (including) | 1.5 (including) |
Netbsd | Netbsd | 1.5.1 (including) | 1.5.1 (including) |
Netbsd | Netbsd | 1.5.2 (including) | 1.5.2 (including) |
Netbsd | Netbsd | 1.5.3 (including) | 1.5.3 (including) |
Netbsd | Netbsd | 1.6 (including) | 1.6 (including) |
Netbsd | Netbsd | 1.6.1 (including) | 1.6.1 (including) |
Netbsd | Netbsd | 1.6.2 (including) | 1.6.2 (including) |
Netbsd | Netbsd | 2.0 (including) | 2.0 (including) |
Netbsd | Netbsd | 2.0.1 (including) | 2.0.1 (including) |
Netbsd | Netbsd | 2.0.2 (including) | 2.0.2 (including) |
Netbsd | Netbsd | 2.0.3 (including) | 2.0.3 (including) |
Netbsd | Netbsd | 2.1 (including) | 2.1 (including) |
Netbsd | Netbsd | 3.0 (including) | 3.0 (including) |
Netbsd | Netbsd | 3.0.1 (including) | 3.0.1 (including) |
Netbsd | Netbsd | 3.0.2 (including) | 3.0.2 (including) |
Netbsd | Netbsd | 3.1 (including) | 3.1 (including) |
Netbsd | Netbsd | 4.0 (including) | 4.0 (including) |
Netbsd | Netbsd | 4.0.1 (including) | 4.0.1 (including) |
Netbsd | Netbsd | 5.0 (including) | 5.0 (including) |