CVE-2018-6927Integer Overflow or Wraparound in Kernel

Severity
7.8HIGHNVD
EPSS
0.0%
top 93.15%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 12
Latest updateMay 14

Description

The futex_requeue function in kernel/futex.c in the Linux kernel before 4.14.15 might allow attackers to cause a denial of service (integer overflow) or possibly have unspecified other impact by triggering a negative wake or requeue value.

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages6 packages

Also affects: Debian Linux 7.0, 8.0, Ubuntu Linux 12.04, 14.04, 16.04, 17.10, Enterprise Linux 7.6

Patches

🔴Vulnerability Details

3
GHSA
GHSA-93fc-35g9-m74x: The futex_requeue function in kernel/futex2022-05-14
OSV
CVE-2018-6927: The futex_requeue function in kernel/futex2018-02-12
CVEList
CVE-2018-6927: The futex_requeue function in kernel/futex2018-02-12

📋Vendor Advisories

10
Ubuntu
Linux kernel vulnerabilities2018-07-02
Ubuntu
Linux kernel vulnerabilities2018-07-02
Ubuntu
Linux kernel (Trusty HWE) vulnerabilities2018-07-02
Ubuntu
Linux kernel (OEM) vulnerabilities2018-07-02
Android
CVE-2018-6927: futex2018-07-01

💬Community

2
Bugzilla
CVE-2018-6927 kernel: Integer overflow in futex.c:futux_requeue can lead to denial of service or unspecified impact [fedora-all]2018-02-13
Bugzilla
CVE-2018-6927 kernel: Integer overflow in futex.c:futux_requeue can lead to denial of service or unspecified impact2018-02-13
CVE-2018-6927 — Integer Overflow or Wraparound | cvebase