CVE-2010-0623
published 2010-02-15CVE-2010-0623: The futex_lock_pi function in kernel/futex.c in the Linux kernel before 2.6.33-rc7 does not properly manage a certain reference count, which allows local users…
PriorityP413medium4.9CVSS 2.0
AVLACLAuNCNINAC
EPSS
0.40%
33.2th percentile
The futex_lock_pi function in kernel/futex.c in the Linux kernel before 2.6.33-rc7 does not properly manage a certain reference count, which allows local users to cause a denial of service (OOPS) via vectors involving an unmount of an ext3 filesystem.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| linux | linux_kernel | < 2.6.33 | 2.6.33 |
| linux | linux_kernel | — | — |
| opensuse | opensuse | — | — |
CVSS provenance
nvdv2.04.9MEDIUMAV:L/AC:L/Au:N/C:N/I:N/A:C
vendor_redhat4.9MEDIUM
vendor_ubuntu4.7MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Linux Kernel 2.6.16.9 futex_lock_pi input validation (Nessus ID 48181 / ID 166481)
vuldb·2026-04-30·CVSS 4.9
CVE-2010-0623 [MEDIUM] Linux Kernel 2.6.16.9 futex_lock_pi input validation (Nessus ID 48181 / ID 166481)
A vulnerability classified as problematic was found in Linux Kernel 2.6.16.9. This affects the function futex_lock_pi. Executing a manipulation can lead to improper input validation.
This vulnerability is handled as CVE-2010-0623. It is possible to launch the attack on the local host. There is not any exploit available.
GHSA
GHSA-h4hr-vrvh-q8pp: The futex_lock_pi function in kernel/futex
ghsa_unreviewed·2022-05-02
CVE-2010-0623 [MEDIUM] GHSA-h4hr-vrvh-q8pp: The futex_lock_pi function in kernel/futex
The futex_lock_pi function in kernel/futex.c in the Linux kernel before 2.6.33-rc7 does not properly manage a certain reference count, which allows local users to cause a denial of service (OOPS) via vectors involving an unmount of an ext3 filesystem.
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2010-03-17·CVSS 4.7
CVE-2010-0307 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Linux kernel vulnerabilities
Mathias Krause discovered that the Linux kernel did not correctly handle
missing ELF interpreters. A local attacker could exploit this to cause the
system to crash, leading to a denial of service. (CVE-2010-0307)
Marcelo Tosatti discovered that the Linux kernel's hardware virtualization
did not correctly handle reading the /dev/port special device. A local
attacker in a guest operating system could issue a specific read that
would cause the host system to crash, leading to a denial of service.
(CVE-2010-0309)
Sebastian Krahmer discovered that the Linux kernel did not correctly
handle netlink connector messages. A local attacker could exploit this
to consume kernel memory, leading to a denial of service. (CVE-2010
Red Hat
kernel: local DoS via futex_lock_pi
vendor_redhat·2010-02-03·CVSS 4.9
CVE-2010-0623 [MEDIUM] kernel: local DoS via futex_lock_pi
kernel: local DoS via futex_lock_pi
The futex_lock_pi function in kernel/futex.c in the Linux kernel before 2.6.33-rc7 does not properly manage a certain reference count, which allows local users to cause a denial of service (OOPS) via vectors involving an unmount of an ext3 filesystem.
Statement: Not vulnerable. This security issue did not affect the Linux kernels as shipped with Red Hat Enterprise Linux 3, 4, 5, and Red Hat Enterprise MRG, as they do not include the upstream change that introduced this flaw.
No detection rules found.
http://bugzilla.kernel.org/show_bug.cgi?id=14256http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=5ecb01cfdf96c5f465192bdb2a4fd4a61a24c6cchttp://lists.opensuse.org/opensuse-security-announce/2010-03/msg00006.htmlhttp://secunia.com/advisories/38922http://www.kernel.org/pub/linux/kernel/v2.6/testing/ChangeLog-2.6.33-rc7http://www.mandriva.com/security/advisories?name=MDVSA-2010:088http://www.openwall.com/lists/oss-security/2010/02/11/2http://www.ubuntu.com/usn/USN-914-1http://www.vupen.com/english/advisories/2010/0638http://bugzilla.kernel.org/show_bug.cgi?id=14256http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=5ecb01cfdf96c5f465192bdb2a4fd4a61a24c6cchttp://lists.opensuse.org/opensuse-security-announce/2010-03/msg00006.htmlhttp://secunia.com/advisories/38922http://www.kernel.org/pub/linux/kernel/v2.6/testing/ChangeLog-2.6.33-rc7http://www.mandriva.com/security/advisories?name=MDVSA-2010:088http://www.openwall.com/lists/oss-security/2010/02/11/2http://www.ubuntu.com/usn/USN-914-1http://www.vupen.com/english/advisories/2010/0638
2010-02-15
Published