CVE-2014-3153

HIGH7.8Veröffentlicht am 7. Juni 2014

The futex_requeue function in kernel/futex.c in the Linux kernel through 3.14.5 does not ensure that calls have two different futex addresses, which allows local users to gain privileges via a crafted FUTEX_REQUEUE command that facilitates unsafe waiter modification.

Aktiv ausgenutzt

  • Seit dem 25. Mai 2022 im CISA-Katalog ausgenutzter Schwachstellen
  • US-Bundesbehörden müssen sie bis zum 15. Juni 2022 beheben (BOD 22-01)
  • Erster Angriff 408 Tage nach der Veröffentlichung beobachtet
  • In Ransomware-Kampagnen eingesetzt

Apply updates per vendor instructions.

Quelle: CISA KEV · 25. Mai 2022 11. Feb. 2021 16. Jan. 2018 25. Apr. 2016 21. Juli 2015

CVSS-Score7.8 / 10CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Herstellerredhat, suse, oracle, linux, opensuse, canonical

Betroffene Produkte

HerstellerProdottoVersioni
linuxlinux kernel< 3.2.60
redhatenterprise linux server aus6.2
opensuseopensuse11.4
suselinux enterprise desktop11
suselinux enterprise high availability extension11
suselinux enterprise real time extension11
suselinux enterprise server11
canonicalubuntu linux12.04
oraclelinux5

Verwandte Artikel

This product uses the NVD API but is not endorsed or certified by the NVD.

CVE-Datenbank