cbcvebase.
CVE-2014-0205
published 2014-09-28

CVE-2014-0205: The futex_wait function in kernel/futex.c in the Linux kernel before 2.6.37 does not properly maintain a certain reference count during requeue operations…

PriorityP421medium6.9CVSS 2.0
AVLACMAuNCCICAC
EPSS
0.66%
48.1th percentile
The futex_wait function in kernel/futex.c in the Linux kernel before 2.6.37 does not properly maintain a certain reference count during requeue operations, which allows local users to cause a denial of service (use-after-free and system crash) or possibly gain privileges via a crafted application that triggers a zero count.

Affected

10 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 2.6.37 (bookworm)linux 2.6.37 (bookworm)
linuxlinux_kernel<= 2.6.36.4
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 2.6.372.6.37
linuxlinux_kernel>= 0 < 2.6.372.6.37
linuxlinux_kernel>= 0 < 2.6.372.6.37
linuxlinux_kernel>= 0 < 2.6.372.6.37

CVSS provenance

nvdv2.06.9MEDIUMAV:L/AC:M/Au:N/C:C/I:C/A:C
osv6.9MEDIUM
vendor_ubuntu7.1HIGH
vendor_debian6.9MEDIUM
vendor_redhat6.9MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.