CVE-2014-3153
The futex_requeue function in kernel/futex.c in the Linux kernel through 3.14.5 does not ensure that calls have two different futex addresses, which allows local users to gain privileges via a crafted FUTEX_REQUEUE command that facilitates unsafe waiter modification.
Aktiv ausgenutzt
- Seit dem 25. Mai 2022 im CISA-Katalog ausgenutzter Schwachstellen
- US-Bundesbehörden müssen sie bis zum 15. Juni 2022 beheben (BOD 22-01)
- Erster Angriff 408 Tage nach der Veröffentlichung beobachtet
- In Ransomware-Kampagnen eingesetzt
Apply updates per vendor instructions.
Quelle: CISA KEV · 25. Mai 2022 11. Feb. 2021 16. Jan. 2018 25. Apr. 2016 21. Juli 2015
CVSS-Score7.8 / 10
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HHerstellerredhat, suse, oracle, linux, opensuse, canonical
Betroffene Produkte
| Hersteller | Prodotto | Versioni |
|---|---|---|
| linux | linux kernel | < 3.2.60 |
| redhat | enterprise linux server aus | 6.2 |
| opensuse | opensuse | 11.4 |
| suse | linux enterprise desktop | 11 |
| suse | linux enterprise high availability extension | 11 |
| suse | linux enterprise real time extension | 11 |
| suse | linux enterprise server | 11 |
| canonical | ubuntu linux | 12.04 |
| oracle | linux | 5 |
Verwandte Artikel
This product uses the NVD API but is not endorsed or certified by the NVD.
