CVE-2014-3153

HIGH7.8Pubblicata il 7 giugno 2014

The futex_requeue function in kernel/futex.c in the Linux kernel through 3.14.5 does not ensure that calls have two different futex addresses, which allows local users to gain privileges via a crafted FUTEX_REQUEUE command that facilitates unsafe waiter modification.

Sfruttata attivamente

  • Nel catalogo CISA delle vulnerabilità sfruttate dal 25 mag 2022
  • Le agenzie federali statunitensi devono correggerla entro il 15 giu 2022 (direttiva BOD 22-01)
  • Primo attacco osservato 408 giorni dopo la divulgazione
  • Usata in campagne ransomware

Apply updates per vendor instructions.

Fonte: CISA KEV · 25 mag 2022 11 feb 2021 16 gen 2018 25 apr 2016 21 lug 2015

Punteggio CVSS7.8 / 10CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Vendorredhat, suse, oracle, linux, opensuse, canonical

Prodotti coinvolti

VendorProdottoVersioni
linuxlinux kernel< 3.2.60
redhatenterprise linux server aus6.2
opensuseopensuse11.4
suselinux enterprise desktop11
suselinux enterprise high availability extension11
suselinux enterprise real time extension11
suselinux enterprise server11
canonicalubuntu linux12.04
oraclelinux5

Articoli correlati

This product uses the NVD API but is not endorsed or certified by the NVD.

Database CVE