CVE-2014-3153

HIGH7.8Published on June 7, 2014

The futex_requeue function in kernel/futex.c in the Linux kernel through 3.14.5 does not ensure that calls have two different futex addresses, which allows local users to gain privileges via a crafted FUTEX_REQUEUE command that facilitates unsafe waiter modification.

Actively exploited

  • In the CISA exploited-vulnerabilities catalogue since May 25, 2022
  • US federal agencies must remediate it by Jun 15, 2022 (BOD 22-01)
  • First attack observed 408 days after disclosure
  • Used in ransomware campaigns

Apply updates per vendor instructions.

Source: CISA KEV · May 25, 2022 Feb 11, 2021 Jan 16, 2018 Apr 25, 2016 Jul 21, 2015

CVSS score7.8 / 10CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Vendorsredhat, suse, oracle, linux, opensuse, canonical

Affected products

VendorsProdottoVersioni
linuxlinux kernel< 3.2.60
redhatenterprise linux server aus6.2
opensuseopensuse11.4
suselinux enterprise desktop11
suselinux enterprise high availability extension11
suselinux enterprise real time extension11
suselinux enterprise server11
canonicalubuntu linux12.04
oraclelinux5

Related articles

This product uses the NVD API but is not endorsed or certified by the NVD.

CVE database