Description
Floating point information leak in the context switch code for Linux 2.4.x only checks the MFH bit but does not verify the FPH owner, which allows local users to read register values of other processes by setting the MFH bit.
References (15)
Core 15
Core References
Third Party Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/20163
Vendor Advisory mailing-list
x_refsource_mlist
http://archives.neohapsis.com/archives/linux/owl/2004-q2/0038.html
Third Party Advisory vendor-advisory
x_refsource_debian
http://www.debian.org/security/2006/dsa-1082
Third Party Advisory vendor-advisory
x_refsource_debian
http://www.debian.org/security/2006/dsa-1070
Third Party Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/20162
Third Party Advisory, VDB Entry vdb-entry
signature
x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10714
Third Party Advisory vendor-advisory
x_refsource_debian
http://www.debian.org/security/2006/dsa-1067
Third Party Advisory vendor-advisory
x_refsource_debian
http://www.debian.org/security/2006/dsa-1069
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/10687
Vendor Advisory x_refsource_misc
https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=124734
Vendor Advisory vendor-advisory
x_refsource_mandrake
http://www.mandriva.com/security/advisories?name=MDKSA-2004:066
Third Party Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/20202
Vendor Advisory vendor-advisory
x_refsource_redhat
http://www.redhat.com/support/errata/RHSA-2004-504.html
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/16644
Third Party Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/20338
Scores
EPSS
0.0011
EPSS Percentile
28.3%
Details
Status
published
Products (10)
gentoo/linux
linux/linux_kernel
2.4.0
mandrakesoft/mandrake_linux
9.1
mandrakesoft/mandrake_linux
9.2
mandrakesoft/mandrake_linux
10.0
mandrakesoft/mandrake_linux_corporate_server
2.1
mandrakesoft/mandrake_multi_network_firewall
8.2
trustix/secure_linux
2
trustix/secure_linux
2.0
trustix/secure_linux
2.1
Published
Dec 06, 2004
Tracked Since
Feb 18, 2026