CVE-2014-3153
linux kernel, redhat enterprise linux server aus, opensuse
Published 7 Jun 2014 · updated 17 Jun 2026 · Analyzed
7.8 High · CVSS 3.1, NVD
Exploited in the wild
CISA added this to its Known Exploited Vulnerabilities catalog on 25 May 2022, with a remediation deadline of 15 Jun 2022 for US federal agencies.
Required action: Apply updates per vendor instructions.
Description
The futex_requeue function in kernel/futex.c in the Linux kernel through 3.14.5 does not ensure that calls have two different futex addresses, which allows local users to gain privileges via a crafted FUTEX_REQUEUE command that facilitates unsafe waiter modification.
References
- git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=e9c243a5a6de0be8e584c604d353412584b592f8 · Broken Link
- linux.oracle.com/errata/ELSA-2014-0771.html · Third Party Advisory
- linux.oracle.com/errata/ELSA-2014-3037.html · Third Party Advisory
- linux.oracle.com/errata/ELSA-2014-3038.html · Third Party Advisory
- linux.oracle.com/errata/ELSA-2014-3039.html · Third Party Advisory
- lists.opensuse.org/opensuse-security-announce/2014-06/msg00014.html · Mailing List, Third Party Advisory
- lists.opensuse.org/opensuse-security-announce/2014-06/msg00018.html · Mailing List, Third Party Advisory
- lists.opensuse.org/opensuse-security-announce/2014-06/msg00025.html · Mailing List, Third Party Advisory
- lists.opensuse.org/opensuse-security-announce/2014-07/msg00006.html · Mailing List, Third Party Advisory
- lists.opensuse.org/opensuse-security-announce/2014-10/msg00006.html · Mailing List, Third Party Advisory
- lists.opensuse.org/opensuse-security-announce/2014-10/msg00007.html · Mailing List, Third Party Advisory
- openwall.com/lists/oss-security/2014/06/05/24 · Mailing List
- openwall.com/lists/oss-security/2014/06/06/20 · Mailing List
- rhn.redhat.com/errata/RHSA-2014-0800.html · Third Party Advisory
- secunia.com/advisories/58500 · Broken Link
- secunia.com/advisories/58990 · Broken Link
- secunia.com/advisories/59029 · Broken Link
- secunia.com/advisories/59092 · Broken Link
- secunia.com/advisories/59153 · Broken Link
- secunia.com/advisories/59262 · Broken Link
- secunia.com/advisories/59309 · Broken Link
- secunia.com/advisories/59386 · Broken Link
- secunia.com/advisories/59599 · Broken Link
- www.debian.org/security/2014/dsa-2949 · Exploit
- www.exploit-db.com/exploits/35370 · Third Party Advisory, VDB Entry