PT-2005-1964 · Linux+1 · Linux Kernel+1
Published
2005-02-22
·
Updated
2023-02-13
·
CVE-2005-0937
CVSS v2.0
1.2
Low
| Vector | AV:L/AC:H/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
Linux kernel versions 2.6.x
Description
The issue is related to some futex functions in futex.c, which perform get user calls while holding the mmap sem semaphore. This could allow local users to cause a deadlock condition in do page fault by triggering get user faults while another thread is executing mmap or other functions.
Recommendations
For Linux kernel version 2.6.x, consider applying a patch that fixes the deadlock condition in futex functions. As a temporary workaround, consider restricting access to futex functions to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux Kernel
Red Hat