{
  "id": "CVE-2014-3153",
  "url": "https://spydr.io/cve/CVE-2014-3153",
  "published": "2014-06-07T14:55:27.240Z",
  "modified": "2026-06-17T00:07:40.877Z",
  "score": 7.8,
  "severity": "high",
  "cvss_version": "3.1",
  "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
  "score_source": "NVD",
  "epss": 0.37233,
  "epss_percentile": 0.9849,
  "exploited": true,
  "kev": {
    "added": "2022-05-25",
    "due": "2022-06-15",
    "action": "Apply updates per vendor instructions.",
    "ransomware": "Unknown",
    "name": "Linux Kernel Privilege Escalation Vulnerability",
    "notes": "https://nvd.nist.gov/vuln/detail/CVE-2014-3153"
  },
  "ssvc_exploitation": "active",
  "vendors": [
    "linux",
    "redhat",
    "opensuse",
    "suse",
    "canonical",
    "oracle"
  ],
  "products": [
    "linux kernel",
    "redhat enterprise linux server aus",
    "opensuse",
    "suse linux enterprise desktop",
    "suse linux enterprise high availability extension",
    "suse linux enterprise real time extension",
    "suse linux enterprise server",
    "canonical ubuntu linux",
    "oracle linux"
  ],
  "cwes": [],
  "description": "The futex_requeue function in kernel/futex.c in the Linux kernel through 3.14.5 does not ensure that calls have two different futex addresses, which allows local users to gain privileges via a crafted FUTEX_REQUEUE command that facilitates unsafe waiter modification.",
  "status": "Analyzed",
  "score_type": "Primary",
  "scores": {
    "cvss_v40": null,
    "cvss_v31": 7.8,
    "cvss_v30": null
  },
  "references": [
    {
      "url": "http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=e9c243a5a6de0be8e584c604d353412584b592f8",
      "tags": [
        "Broken Link"
      ]
    },
    {
      "url": "http://linux.oracle.com/errata/ELSA-2014-0771.html",
      "tags": [
        "Third Party Advisory"
      ]
    },
    {
      "url": "http://linux.oracle.com/errata/ELSA-2014-3037.html",
      "tags": [
        "Third Party Advisory"
      ]
    },
    {
      "url": "http://linux.oracle.com/errata/ELSA-2014-3038.html",
      "tags": [
        "Third Party Advisory"
      ]
    },
    {
      "url": "http://linux.oracle.com/errata/ELSA-2014-3039.html",
      "tags": [
        "Third Party Advisory"
      ]
    },
    {
      "url": "http://lists.opensuse.org/opensuse-security-announce/2014-06/msg00014.html",
      "tags": [
        "Mailing List",
        "Third Party Advisory"
      ]
    },
    {
      "url": "http://lists.opensuse.org/opensuse-security-announce/2014-06/msg00018.html",
      "tags": [
        "Mailing List",
        "Third Party Advisory"
      ]
    },
    {
      "url": "http://lists.opensuse.org/opensuse-security-announce/2014-06/msg00025.html",
      "tags": [
        "Mailing List",
        "Third Party Advisory"
      ]
    },
    {
      "url": "http://lists.opensuse.org/opensuse-security-announce/2014-07/msg00006.html",
      "tags": [
        "Mailing List",
        "Third Party Advisory"
      ]
    },
    {
      "url": "http://lists.opensuse.org/opensuse-security-announce/2014-10/msg00006.html",
      "tags": [
        "Mailing List",
        "Third Party Advisory"
      ]
    },
    {
      "url": "http://lists.opensuse.org/opensuse-security-announce/2014-10/msg00007.html",
      "tags": [
        "Mailing List",
        "Third Party Advisory"
      ]
    },
    {
      "url": "http://openwall.com/lists/oss-security/2014/06/05/24",
      "tags": [
        "Mailing List"
      ]
    },
    {
      "url": "http://openwall.com/lists/oss-security/2014/06/06/20",
      "tags": [
        "Mailing List"
      ]
    },
    {
      "url": "http://rhn.redhat.com/errata/RHSA-2014-0800.html",
      "tags": [
        "Third Party Advisory"
      ]
    },
    {
      "url": "http://secunia.com/advisories/58500",
      "tags": [
        "Broken Link"
      ]
    },
    {
      "url": "http://secunia.com/advisories/58990",
      "tags": [
        "Broken Link"
      ]
    },
    {
      "url": "http://secunia.com/advisories/59029",
      "tags": [
        "Broken Link"
      ]
    },
    {
      "url": "http://secunia.com/advisories/59092",
      "tags": [
        "Broken Link"
      ]
    },
    {
      "url": "http://secunia.com/advisories/59153",
      "tags": [
        "Broken Link"
      ]
    },
    {
      "url": "http://secunia.com/advisories/59262",
      "tags": [
        "Broken Link"
      ]
    },
    {
      "url": "http://secunia.com/advisories/59309",
      "tags": [
        "Broken Link"
      ]
    },
    {
      "url": "http://secunia.com/advisories/59386",
      "tags": [
        "Broken Link"
      ]
    },
    {
      "url": "http://secunia.com/advisories/59599",
      "tags": [
        "Broken Link"
      ]
    },
    {
      "url": "http://www.debian.org/security/2014/dsa-2949",
      "tags": [
        "Exploit"
      ]
    },
    {
      "url": "http://www.exploit-db.com/exploits/35370",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ]
    }
  ],
  "nvd_url": "https://nvd.nist.gov/vuln/detail/CVE-2014-3153",
  "covered_in": [],
  "attribution": [
    {
      "source": "NVD",
      "url": "https://nvd.nist.gov",
      "notice": "This product uses data from the NVD API but is not endorsed or certified by the NVD."
    },
    {
      "source": "CISA KEV",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "notice": "Known exploited vulnerabilities from the CISA KEV catalog."
    },
    {
      "source": "FIRST EPSS",
      "url": "https://www.first.org/epss",
      "notice": "Exploit prediction scores from FIRST EPSS."
    }
  ]
}
