Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [day] [month] [year] [list]
Date: Wed, 10 Nov 2010 11:08:52 +0800
From: Eugene Teo <>
CC: "Steven M. Christey" <>
Subject: CVE-2010-3086 kernel panic via futex

Discovered by Tavis Ormandy, the exception fixup code for the 
__futex_atomic_op1, __futex_atomic_op2, and 
futex_atomic_cmpxchg-_inatomic() macros replaced the LOCK prefix with a 
NOP instruction. This can cause the exceptions to not match the 
exception table fault fixup. A local, unprivileged user could use this 
flaw to cause a denial of service. This is assigned with CVE-2010-3086.

Thanks, Eugene
main(i) { putchar(182623909 >> (i-1) * 5&31|!!(i<7)<<6) && main(++i); }

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.