CVE-2014-3153
The futex_requeue function in kernel/futex.c in the Linux kernel through 3.14.5 does not ensure that calls have two different futex addresses, which allows local users to gain privileges via a crafted FUTEX_REQUEUE command that facilitates unsafe waiter modification.
Actively exploited
- In the CISA exploited-vulnerabilities catalogue since May 25, 2022
- US federal agencies must remediate it by Jun 15, 2022 (BOD 22-01)
- First attack observed 408 days after disclosure
- Used in ransomware campaigns
Apply updates per vendor instructions.
Source: CISA KEV · May 25, 2022 Feb 11, 2021 Jan 16, 2018 Apr 25, 2016 Jul 21, 2015
CVSS score7.8 / 10
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HVendorsredhat, suse, oracle, linux, opensuse, canonical
Affected products
| Vendors | Prodotto | Versioni |
|---|---|---|
| linux | linux kernel | < 3.2.60 |
| redhat | enterprise linux server aus | 6.2 |
| opensuse | opensuse | 11.4 |
| suse | linux enterprise desktop | 11 |
| suse | linux enterprise high availability extension | 11 |
| suse | linux enterprise real time extension | 11 |
| suse | linux enterprise server | 11 |
| canonical | ubuntu linux | 12.04 |
| oracle | linux | 5 |
Related articles
This product uses the NVD API but is not endorsed or certified by the NVD.
