Missing release of memory after effective lifetime in Linux kernel - CVE-2004-0565

 

Missing release of memory after effective lifetime in Linux kernel - CVE-2004-0565

Published: December 6, 2004 / Updated: October 11, 2017


Vulnerability identifier: #VU99942
CSH Severity: Low
CVSS v4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2004-0565
CWE-ID: CWE-401
Exploitation vector: Local access
Exploit availability: No public exploit available
Vendor: Linux Foundation
Affected software:
Linux kernel

Detailed vulnerability description

The vulnerability allows a local user to gain access to sensitive information.

Floating point information leak in the context switch code for Linux 2.4.x only checks the MFH bit but does not verify the FPH owner, which allows local users to read register values of other processes by setting the MFH bit.


How to mitigate CVE-2004-0565

Install update from vendor's repository.

Sources