CVE-2010-0623
Summary
| CVE | CVE-2010-0623 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2010-02-15 18:30:00 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | The futex_lock_pi function in kernel/futex.c in the Linux kernel before 2.6.33-rc7 does not properly manage a certain reference count, which allows local users to cause a denial of service (OOPS) via vectors involving an unmount of an ext3 filesystem. |
Risk And Classification
Primary CVSS: v2.0 4.9 from [email protected]
AV:L/AC:L/Au:N/C:N/I:N/A:C
Problem Types: NVD-CWE-noinfo | n/a
CVSS v2.0 Breakdown
Access Vector
LocalAccess Complexity
LowAuthentication
NoneConfidentiality
NoneIntegrity
NoneAvailability
CompleteAV:L/AC:L/Au:N/C:N/I:N/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Canonical | Ubuntu Linux | 6.06 | All | All | All |
| Operating System | Canonical | Ubuntu Linux | 8.04 | All | All | All |
| Operating System | Canonical | Ubuntu Linux | 8.10 | All | All | All |
| Operating System | Canonical | Ubuntu Linux | 9.04 | All | All | All |
| Operating System | Canonical | Ubuntu Linux | 9.10 | All | All | All |
| Operating System | Linux | Linux Kernel | All | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.33 | - | All | All |
| Operating System | Linux | Linux Kernel | 2.6.33 | rc1 | All | All |
| Operating System | Linux | Linux Kernel | 2.6.33 | rc2 | All | All |
| Operating System | Linux | Linux Kernel | 2.6.33 | rc3 | All | All |
| Operating System | Linux | Linux Kernel | 2.6.33 | rc4 | All | All |
| Operating System | Linux | Linux Kernel | 2.6.33 | rc5 | All | All |
| Operating System | Linux | Linux Kernel | 2.6.33 | rc6 | All | All |
| Operating System | Opensuse | Opensuse | 11.2 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| [security-announce] SUSE Security Announcement: Linux kernel (SUSE-SA:20 | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | Mailing List, Third Party Advisory |
| USN-914-1: Linux kernel vulnerabilities | Ubuntu | af854a3a-2127-422b-91ae-364da2661108 | www.ubuntu.com | Third Party Advisory |
| Support / Security / Advisories / / MDVSA-2010:088 | Mandriva | af854a3a-2127-422b-91ae-364da2661108 | www.mandriva.com | Third Party Advisory |
| 404: File not found | af854a3a-2127-422b-91ae-364da2661108 | www.kernel.org | Broken Link |
| oss-security - Re: CVE request - kernel: futex: Handle user space corruption gracefully | af854a3a-2127-422b-91ae-364da2661108 | www.openwall.com | Mailing List, Third Party Advisory |
| Bug 14256 – kernel BUG at fs/ext3/super.c:435 | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.kernel.org | Issue Tracking, Patch, Vendor Advisory |
| Ubuntu update for linux and linux-source-2.6.15 - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Third Party Advisory |
| Webmail- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Third Party Advisory |
| kernel/git/torvalds/linux.git - Linux kernel source tree | af854a3a-2127-422b-91ae-364da2661108 | git.kernel.org | |
| kernel/git/torvalds/linux.git - Linux kernel source tree | MITRE | git.kernel.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
| Organization | Published | Contributor | Statement |
|---|---|---|---|
| Red Hat | 2010-03-12 | Vincent Danen | Not vulnerable. This security issue did not affect the Linux kernels as shipped with Red Hat Enterprise Linux 3, 4, 5, and Red Hat Enterprise MRG, as they do not include the upstream change that introduced this flaw. |
There are currently no legacy QID mappings associated with this CVE.