CVE-2014-0205: Linux Kernel
Medium severity, CVSS 6.9. EPSS: 0.7% chance of exploitation in the next 30 days.
The futex_wait function in kernel/futex.c in the Linux kernel before 2.6.37 does not properly maintain a certain reference count during requeue operations, which allows local users to cause a denial of service (use-after-free and system crash) or possibly gain privileges via a crafted application that triggers a zero count.
Affected products
- Linux Linux Kernel: up to and including 2.6.36.4; version 2.6.36 only; version 2.6.36.1 only; version 2.6.36.2 only; version 2.6.36.3 only
Published 2014-09-28. Last modified 2026-06-17.