Lucene search

K
ubuntucveUbuntu.comUB:CVE-2014-0205
HistorySep 28, 2014 - 12:00 a.m.

CVE-2014-0205

2014-09-2800:00:00
ubuntu.com
ubuntu.com
14

6.9 Medium

CVSS2

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:M/Au:N/C:C/I:C/A:C

0.001 Low

EPSS

Percentile

44.6%

The futex_wait function in kernel/futex.c in the Linux kernel before 2.6.37
does not properly maintain a certain reference count during requeue
operations, which allows local users to cause a denial of service
(use-after-free and system crash) or possibly gain privileges via a crafted
application that triggers a zero count.

Bugs

Notes

Author Note
jdstrand android kernels (flo, goldfish, grouper, maguro, mako and manta) are not supported on the Ubuntu Touch 14.04 preview kernels linux-lts-saucy no longer receives official support linux-lts-quantal no longer receives official support
OSVersionArchitecturePackageVersionFilename
ubuntu10.04noarchlinux< 2.6.32-27.49UNKNOWN
ubuntu10.04noarchlinux-ec2< 2.6.32-311.23UNKNOWN

6.9 Medium

CVSS2

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:M/Au:N/C:C/I:C/A:C

0.001 Low

EPSS

Percentile

44.6%