CVE-2014-0205
published 2014-09-28CVE-2014-0205: The futex_wait function in kernel/futex.c in the Linux kernel before 2.6.37 does not properly maintain a certain reference count during requeue operations…
PriorityP421medium6.9CVSS 2.0
AVLACMAuNCCICAC
EPSS
0.66%
48.1th percentile
The futex_wait function in kernel/futex.c in the Linux kernel before 2.6.37 does not properly maintain a certain reference count during requeue operations, which allows local users to cause a denial of service (use-after-free and system crash) or possibly gain privileges via a crafted application that triggers a zero count.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 2.6.37 (bookworm) | linux 2.6.37 (bookworm) |
| linux | linux_kernel | <= 2.6.36.4 | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 0 < 2.6.37 | 2.6.37 |
| linux | linux_kernel | >= 0 < 2.6.37 | 2.6.37 |
| linux | linux_kernel | >= 0 < 2.6.37 | 2.6.37 |
| linux | linux_kernel | >= 0 < 2.6.37 | 2.6.37 |
CVSS provenance
nvdv2.06.9MEDIUMAV:L/AC:M/Au:N/C:C/I:C/A:C
osv6.9MEDIUM
vendor_ubuntu7.1HIGH
vendor_debian6.9MEDIUM
vendor_redhat6.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kernel: futex: refcount issue in case of requeue
vendor_redhat·2014-09-09·CVSS 6.9
CVE-2014-0205 [MEDIUM] CWE-682 kernel: futex: refcount issue in case of requeue
kernel: futex: refcount issue in case of requeue
The futex_wait function in kernel/futex.c in the Linux kernel before 2.6.37 does not properly maintain a certain reference count during requeue operations, which allows local users to cause a denial of service (use-after-free and system crash) or possibly gain privileges via a crafted application that triggers a zero count.
A flaw was found in the way the Linux kernel's futex subsystem handled reference counting when requeuing futexes during futex_wait(). A local, unprivileged user could use this flaw to zero out the reference counter of an inode or an mm struct that backs up the memory area of the futex, which could lead to a use-after-free flaw, resulting in a system crash or, potentially, privilege escalation.
Statement: This issue doe
Debian
CVE-2014-0205: linux - The futex_wait function in kernel/futex.c in the Linux kernel before 2.6.37 does...
vendor_debian·2014·CVSS 6.9
CVE-2014-0205 [MEDIUM] CVE-2014-0205: linux - The futex_wait function in kernel/futex.c in the Linux kernel before 2.6.37 does...
The futex_wait function in kernel/futex.c in the Linux kernel before 2.6.37 does not properly maintain a certain reference count during requeue operations, which allows local users to cause a denial of service (use-after-free and system crash) or possibly gain privileges via a crafted application that triggers a zero count.
Scope: local
bookworm: resolved (fixed in 2.6.37)
bullseye: resolved (fixed in 2.6.37)
forky: resolved (fixed in 2.6.37)
sid: resolved (fixed in 2.6.37)
trixie: resolved (fixed in 2.6.37)
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2011-01-10·CVSS 7.1
CVE-2010-3698 [HIGH] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Multiple security flaws in Linux kernel.
Louis Rilling and Matthieu Fertré reported a use after free error in the
Linux kernel's futex_wait function. A local user could exploit this flaw to
cause a denial of service (system crash) or possibly gain privileges via a
specially crafted application. (CVE-2014-0205)
Ben Hawkes discovered that the Linux kernel did not correctly filter
registers on 64bit kernels when performing 32bit system calls. On a 64bit
system, a local attacker could manipulate 32bit system calls to gain root
privileges. (CVE-2010-3301)
Dan Rosenberg discovered that the btrfs filesystem did not correctly
validate permissions when using the clone function. A local attacker could
overwrite the contents of file handles that were o
Cisco
Multiple Vulnerabilities in OpenSSL (January 2015) Affecting Cisco Products
vendor_cisco
CVE-2015-0205 Multiple Vulnerabilities in OpenSSL (January 2015) Affecting Cisco Products
CVE-2015-0205: Multiple Vulnerabilities in OpenSSL (January 2015) Affecting Cisco Products
Multiple Cisco products incorporate a version of the OpenSSL package affected by one or more vulnerabilities that could allow an unauthenticated, remote attacker to cause a denial of service condition or perform a man-in-the-middle attack. On January 8, 2015, the OpenSSL Project released a security advisory detailing eight distinct vulnerabilities. The vulnerabilities are referenced in this document as follows: CVE-2014-3571: OpenSSL DTLS Message Processing Denial of Service Vulnerability CVE-2015-0206: OpenSSL dtls1_buffer_record Function DTLS Message Processing Denial of Service Vulnerability CVE-2014-3569: OpenSSL no-ssl3 Option NULL Pointer Dereference Vulnerability CVE-2014-3572: OpenSSL Ellipti
GHSA
GHSA-cwrh-45v3-q8mf: The futex_wait function in kernel/futex
ghsa_unreviewed·2022-05-17
CVE-2014-0205 [MEDIUM] CWE-119 GHSA-cwrh-45v3-q8mf: The futex_wait function in kernel/futex
The futex_wait function in kernel/futex.c in the Linux kernel before 2.6.37 does not properly maintain a certain reference count during requeue operations, which allows local users to cause a denial of service (use-after-free and system crash) or possibly gain privileges via a crafted application that triggers a zero count.
OSV
CVE-2014-0205: The futex_wait function in kernel/futex
osv·2014-09-28·CVSS 6.9
CVE-2014-0205 [MEDIUM] CVE-2014-0205: The futex_wait function in kernel/futex
The futex_wait function in kernel/futex.c in the Linux kernel before 2.6.37 does not properly maintain a certain reference count during requeue operations, which allows local users to cause a denial of service (use-after-free and system crash) or possibly gain privileges via a crafted application that triggers a zero count.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-0205 kernel: futex: refcount issue in case of requeue
bugzilla·2014-05-05·CVSS 6.9
CVE-2014-0205 [MEDIUM] CVE-2014-0205 kernel: futex: refcount issue in case of requeue
CVE-2014-0205 kernel: futex: refcount issue in case of requeue
A flaw was found in the way the Linux kernel's futex subsystem handled
reference counting in case of futex requeue during futex_wait().
An unprivileged local user could use this flaw to crash the system or,
potentially, escalate their privileges on the system by overputting
reference counter on either inode or mm that backs up the memory area of
the futex, leading to use-after-free.
References:
https://lkml.org/lkml/2010/9/16/99
Upstream fix:
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=7ada876a8703f23befbb20a7465a702ee39b1704
Acknowledgements:
The security impact of this issue was discovered by Mateusz Guzik of Red Hat.
Discussion:
Statement:
This issue does not affect the Linux kernel pac
Bugzilla
CVE-2014-0058 Red Hat JBoss EAP6: Plain text password logging during security audit
bugzilla·2014-02-11·CVSS 1.9
CVE-2014-0058 [LOW] CVE-2014-0058 Red Hat JBoss EAP6: Plain text password logging during security audit
CVE-2014-0058 Red Hat JBoss EAP6: Plain text password logging during security audit
It was identified that web auditing, as provided by Red Hat JBoss Enterprise Application Platform 6, logged request parameters in plain text. This may include passwords used for authentication mechanisms such as BASIC and FORMAUTH. A local attacker, with access to audit logs, could compromise application/server credentials.
Discussion:
This issue has been addressed in following products:
Red Hat JBoss Enterprise Application Platform 6.2.1
Via RHSA-2014:0205 https://rhn.redhat.com/errata/RHSA-2014-0205.html
---
This issue has been addressed in following products:
JBEAP 6.2 for RHEL 5
JBEAP 6.2 for RHEL 6
Via RHSA-2014:0204 https://rhn.redhat.com/errata/RHSA-2014-0204.html
---
This issue has been a
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=7ada876a8703f23befbb20a7465a702ee39b1704http://mirror.linux.org.au/linux/kernel/v2.6/ChangeLog-2.6.37http://rhn.redhat.com/errata/RHSA-2014-1365.htmlhttp://rhn.redhat.com/errata/RHSA-2014-1763.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=1094455https://github.com/torvalds/linux/commit/7ada876a8703f23befbb20a7465a702ee39b1704http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=7ada876a8703f23befbb20a7465a702ee39b1704http://mirror.linux.org.au/linux/kernel/v2.6/ChangeLog-2.6.37http://rhn.redhat.com/errata/RHSA-2014-1365.htmlhttp://rhn.redhat.com/errata/RHSA-2014-1763.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=1094455https://github.com/torvalds/linux/commit/7ada876a8703f23befbb20a7465a702ee39b1704
2014-09-28
Published