CVE-2018-6927: Integer Overflow
Last updated 4 July 2026
Other sources
The futexrequeue function in kernel/futex.c in the Linux kernel before 4.14.15 might allow attackers to cause a denial of service (integer overflow) or possibly have unspecified other impact by triggering a negative wake or requeue value.
— Launchpad
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 4.14.15 - Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 5.10.223-1Fixed in 5.10.262-1Fixed in 6.1.176-1Fixed in 6.1.180-1Fixed in 6.12.94-1Fixed in 6.12.101-1Fixed in 7.1.7-1Fixed in 7.1.8-1 - Upgrade
Upgrade
Linux kernelto a version that resolves this vulnerability.Fixed in 4.14.15 - Compensating control
Mitigate potential impact of a futex_requeue integer overflow by restricting attacker access to systems that process untrusted inputs (e.g., limit which users/containers can trigger futex operations) until the kernel is upgraded.
Event History
Frequently Asked Questions
What is the severity of CVE-2018-6927?
The severity of CVE-2018-6927 is significant as it can lead to denial of service or potentially other impacts.
How do I fix CVE-2018-6927?
To fix CVE-2018-6927, ensure that your Linux kernel version is upgraded to at least 4.14.15 or a later version.
Which systems are affected by CVE-2018-6927?
CVE-2018-6927 affects multiple systems including certain versions of Debian, Ubuntu, and Red Hat Enterprise Linux.
Can CVE-2018-6927 lead to exploits?
Yes, CVE-2018-6927 can be exploited by attackers to cause denial of service due to integer overflow vulnerabilities.
Is CVE-2018-6927 present in the latest Linux kernel versions?
CVE-2018-6927 is not present in Linux kernel versions that are newer than 4.14.15.