CVE-2010-0623

Linux Kernel < 2.6.33 - Denial of Service via futex_lock_pi Reference Count Mismanagement

Title source: llm
STIX 2.1

Description

The futex_lock_pi function in kernel/futex.c in the Linux kernel before 2.6.33-rc7 does not properly manage a certain reference count, which allows local users to cause a denial of service (OOPS) via vectors involving an unmount of an ext3 filesystem.

References (9)

Core 9
Core References
Third Party Advisory vendor-advisory x_refsource_ubuntu
http://www.ubuntu.com/usn/USN-914-1
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2010/0638
Issue Tracking, Patch, Vendor Advisory x_refsource_confirm
http://bugzilla.kernel.org/show_bug.cgi?id=14256
Third Party Advisory vendor-advisory x_refsource_mandriva
http://www.mandriva.com/security/advisories?name=MDVSA-2010:088
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/38922
Mailing List, Third Party Advisory vendor-advisory x_refsource_suse
http://lists.opensuse.org/opensuse-security-announce/2010-03/msg00006.html
Mailing List, Third Party Advisory mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2010/02/11/2

Scores

EPSS 0.0040
EPSS Percentile 32.8%

Details

Status published
Products (8)
canonical/ubuntu_linux 6.06
canonical/ubuntu_linux 8.04
canonical/ubuntu_linux 8.10
canonical/ubuntu_linux 9.04
canonical/ubuntu_linux 9.10
linux/linux_kernel 2.6.33 (7 CPE variants)
linux/linux_kernel < 2.6.33
opensuse/opensuse 11.2
Published Feb 15, 2010
Tracked Since Feb 18, 2026