CVE-2014-0205

CVSS v2.0 6.9 (Medium)
69% Progress
EPSS 0.11 % (45th)
0.11% Progress
Affected Products 1
Advisories 4

The futex_wait function in kernel/futex.c in the Linux kernel before 2.6.37 does not properly maintain a certain reference count during requeue operations, which allows local users to cause a denial of service (use-after-free and system crash) or possibly gain privileges via a crafted application that triggers a zero count.

Weaknesses
CWE-119
Improper Restriction of Operations within the Bounds of a Memory Buffer
CVE Status
PUBLISHED
CNA
Red Hat, Inc.
Published Date
2014-09-28 19:55:05
(10 years ago)
Updated Date
2023-02-13 00:37:23
(19 months ago)

Affected Products

Loading...
Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Linux Kernel 2.6.36.4 and prior versions cpe:2.3:o:linux:linux_kernel <= 2.6.36.4
  Linux Kernel 2.6.36 cpe:2.3:o:linux:linux_kernel:2.6.36
  Linux Kernel 2.6.36 Rc1 cpe:2.3:o:linux:linux_kernel:2.6.36:rc1
  Linux Kernel 2.6.36 Rc2 cpe:2.3:o:linux:linux_kernel:2.6.36:rc2
  Linux Kernel 2.6.36 Rc3 cpe:2.3:o:linux:linux_kernel:2.6.36:rc3
  Linux Kernel 2.6.36 Rc4 cpe:2.3:o:linux:linux_kernel:2.6.36:rc4
  Linux Kernel 2.6.36 Rc5 cpe:2.3:o:linux:linux_kernel:2.6.36:rc5
  Linux Kernel 2.6.36 Rc6 cpe:2.3:o:linux:linux_kernel:2.6.36:rc6
  Linux Kernel 2.6.36 Rc7 cpe:2.3:o:linux:linux_kernel:2.6.36:rc7
  Linux Kernel 2.6.36 Rc8 cpe:2.3:o:linux:linux_kernel:2.6.36:rc8
  Linux Kernel 2.6.36.1 cpe:2.3:o:linux:linux_kernel:2.6.36.1
  Linux Kernel 2.6.36.2 cpe:2.3:o:linux:linux_kernel:2.6.36.2
  Linux Kernel 2.6.36.3 cpe:2.3:o:linux:linux_kernel:2.6.36.3
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...