Other than apparently commonly assumed, the bound instruction does not require the corresponding IDT entry to have DPL 3. From: Jan Beulich --- 2.6.14/arch/i386/kernel/traps.c 2005-10-28 02:02:08.000000000 +0200 +++ 2.6.14-i386-bound/arch/i386/kernel/traps.c 2005-11-04 17:00:47.000000000 +0100 @@ -1081,9 +1081,9 @@ void __init trap_init(void) set_trap_gate(0,÷_error); set_intr_gate(1,&debug); set_intr_gate(2,&nmi); - set_system_intr_gate(3, &int3); /* int3-5 can be called from all */ + set_system_intr_gate(3, &int3); /* int3/4 can be called from all */ set_system_gate(4,&overflow); - set_system_gate(5,&bounds); + set_trap_gate(5,&bounds); set_trap_gate(6,&invalid_op); set_trap_gate(7,&device_not_available); set_task_gate(8,GDT_ENTRY_DOUBLEFAULT_TSS);