Junglewise Threat Intelligence

CVE-2014-3153: Linux Kernel Privilege Escalation Vulnerability

CVE-2014-3153 · Severity: critical · CVSS 7.8 · Exploited in the wild · Published 2022-05-25

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The futex_requeue function in kernel/futex.c in the Linux kernel does not ensure that calls have two different futex addresses. This flaw allows local users to gain privileges via a crafted FUTEX_REQUEUE command that facilitates unsafe waiter modification.

Affected products

  • Linux Linux Kernel through 3.14.5

Timeline

  • 2014-06-05: disclosed: Public discussion on oss-security mailing list
  • 2022-05-25: kev added: Added to CISA Known Exploited Vulnerabilities Catalog

Related threats