CVE-2014-3153
The futex_requeue function in kernel/futex.c in the Linux kernel through 3.14.5 does not ensure that calls have two different futex addresses, which allows local users to gain privileges via a crafted FUTEX_REQUEUE command that facilitates unsafe waiter modification.
Explotada activamente
- En el catálogo CISA de vulnerabilidades explotadas desde el 25 may 2022
- Las agencias federales de EE. UU. deben corregirla antes del 15 jun 2022 (BOD 22-01)
- Primer ataque observado 408 días después de la divulgación
- Utilizada en campañas de ransomware
Apply updates per vendor instructions.
Fuente: CISA KEV · 25 may 2022 11 feb 2021 16 ene 2018 25 abr 2016 21 jul 2015
Puntuación CVSS7.8 / 10
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HFabricantesredhat, suse, oracle, linux, opensuse, canonical
Productos afectados
| Fabricantes | Prodotto | Versioni |
|---|---|---|
| linux | linux kernel | < 3.2.60 |
| redhat | enterprise linux server aus | 6.2 |
| opensuse | opensuse | 11.4 |
| suse | linux enterprise desktop | 11 |
| suse | linux enterprise high availability extension | 11 |
| suse | linux enterprise real time extension | 11 |
| suse | linux enterprise server | 11 |
| canonical | ubuntu linux | 12.04 |
| oracle | linux | 5 |
Artículos relacionados
This product uses the NVD API but is not endorsed or certified by the NVD.
