CVE-2014-0205

Severity CVSS v4.0:
Pending analysis
Type:
CWE-119 Buffer Errors
Publication date:
28/09/2014
Last modified:
12/04/2025

Description

The futex_wait function in kernel/futex.c in the Linux kernel before 2.6.37 does not properly maintain a certain reference count during requeue operations, which allows local users to cause a denial of service (use-after-free and system crash) or possibly gain privileges via a crafted application that triggers a zero count.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 2.6.36.4 (including)
cpe:2.3:o:linux:linux_kernel:2.6.36:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.36:rc1:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.36:rc2:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.36:rc3:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.36:rc4:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.36:rc5:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.36:rc6:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.36:rc7:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.36:rc8:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.36.1:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.36.2:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.36.3:*:*:*:*:*:*:*