CVE-2007-0257

HIGH

grsecurity PaX - Privilege Escalation

Title source: llm

Description

Unspecified vulnerability in the expand_stack function in grsecurity PaX allows local users to gain privileges via unspecified vectors. NOTE: the grsecurity developer has disputed this issue, stating that "the function they claim the vulnerability to be in is a trivial function, which can, and has been, easily checked for any supposed vulnerabilities." The developer also cites a past disclosure that was not proven. As of 20070120, the original researcher has released demonstration code

Exploits (1)

exploitdb WORKING POC VERIFIED
by anonymous · clocallinux
https://www.exploit-db.com/exploits/29446

Scores

CVSS v3 7.8
EPSS 0.0026
EPSS Percentile 49.7%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

Status published
Products (12)
grsecurity/grsecurity_kernel_patch 1.9.4
grsecurity/grsecurity_kernel_patch 2.0.1
grsecurity/grsecurity_kernel_patch 2.0.2
grsecurity/grsecurity_kernel_patch 2.1.0
grsecurity/grsecurity_kernel_patch 2.1.1
grsecurity/grsecurity_kernel_patch 2.1.2
grsecurity/grsecurity_kernel_patch 2.1.3
grsecurity/grsecurity_kernel_patch 2.1.4
grsecurity/grsecurity_kernel_patch 2.1.5
grsecurity/grsecurity_kernel_patch 2.1.6
... and 2 more
Published Jan 16, 2007
Tracked Since Feb 18, 2026