Vulnerability Report

CVE-2004-0565

Title: Linux kernel floating point information leak

Information Disclosure

Proof Of Concept

No public PoC currently indexed for CVE-2004-0565.

CWE Category NVD-CWE-noinfo
Published Date Dec 06, 2004
Modified Date Apr 03, 2025
Exploit Status Not Found
Score 2.1 CVSS v2.0
Exploit Probability (EPSS)
0.11%

Vulnerability Summary

CVE-2004-0565: Floating point information leak in the context switch code for Linux 2.4.x only checks the MFH bit but does not verify the FPH owner, which allows local users to read register values of other processes by setting the MFH bit.

Impacted Vendors

Reference Links

http://archives.neohapsis.com/archives/linux/owl/2004-q2/0038.html http://secunia.com/advisories/20162 http://secunia.com/advisories/20163 http://secunia.com/advisories/20202 http://secunia.com/advisories/20338 http://www.debian.org/security/2006/dsa-1067 http://www.debian.org/security/2006/dsa-1069 http://www.debian.org/security/2006/dsa-1070 http://www.debian.org/security/2006/dsa-1082 http://www.mandriva.com/security/advisories?name=MDKSA-2004:066 http://www.redhat.com/support/errata/RHSA-2004-504.html http://www.securityfocus.com/bid/10687 https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=124734 https://exchange.xforce.ibmcloud.com/vulnerabilities/16644 https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10714 http://archives.neohapsis.com/archives/linux/owl/2004-q2/0038.html http://secunia.com/advisories/20162 http://secunia.com/advisories/20163 http://secunia.com/advisories/20202 http://secunia.com/advisories/20338 http://www.debian.org/security/2006/dsa-1067 http://www.debian.org/security/2006/dsa-1069 http://www.debian.org/security/2006/dsa-1070 http://www.debian.org/security/2006/dsa-1082 http://www.mandriva.com/security/advisories?name=MDKSA-2004:066 http://www.redhat.com/support/errata/RHSA-2004-504.html http://www.securityfocus.com/bid/10687 https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=124734 https://exchange.xforce.ibmcloud.com/vulnerabilities/16644 https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10714
CVSS v2.0
Source Entity [email protected]
Severity LOW
2.1
Access Vector
N/A
Authentication
N/A
RAW VECTOR AV:L/AC:L/Au:N/C:P/I:N/A:N

Associated Attack Patterns (CAPEC)

Total: Patterns

CVE-2004-0565 Exploits & PoCs (Proof Of Concept)

No public PoCs found in our database for this CVE.

MODIFIED

Vulnerability data or affected products updated.

PUBLISHED

Vulnerability first announced in NVD.

Attack Vector Matrix

Access Vector N/A
Complexity N/A
Privileges N/A
Interaction NONE
CVSS Vector String AV:L/AC:L/Au:N/C:P/I:N/A:N

Affected Stack

No specific products linked.