CVE-2014-3153

HIGHCVSS 7.8/10Actively ExploitedEPSS 37.23%

Last modified

CVE-2014-3153 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. The futex_requeue function in kernel/futex.c in the Linux kernel through 3.14.5 does not ensure that calls have two different futex addresses, which allows local users to gain privileges via a crafted FUTEX_REQUEUE command that facilitates unsafe waiter modification.. CISA has confirmed active exploitation in the wild. EPSS estimates a 37.23% chance of exploitation in the next 30 days.

Description

The futex_requeue function in kernel/futex.c in the Linux kernel through 3.14.5 does not ensure that calls have two different futex addresses, which allows local users to gain privileges via a crafted FUTEX_REQUEUE command that facilitates unsafe waiter modification.

Metrics

CVSS 3.1
7.8/10

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS Probability
37.23%

98.3th percentile

Probability of exploitation in the next 30 days. Learn more

Exploitation Status

This vulnerability is listed in CISA’s Known Exploited Vulnerabilities catalog, confirming active exploitation in the wild. Federal agencies must remediate by .

Affected Software

VendorProductVersionsUpdate
LinuxLinux Kernel< 3.2.60
LinuxLinux Kernel>= 3.3, < 3.4.92
LinuxLinux Kernel>= 3.5, < 3.10.42
LinuxLinux Kernel>= 3.11, < 3.12.22
LinuxLinux Kernel>= 3.13, < 3.14.6
RedhatEnterprise Linux Server Aus6.2
OpensuseOpensuse11.4
SuseLinux Enterprise Desktop11Sp3
SuseLinux Enterprise High Availability Extension11Sp3
SuseLinux Enterprise Real Time Extension11Sp3
SuseLinux Enterprise Server11
CanonicalUbuntu Linux12.04
CanonicalUbuntu Linux14.04
OracleLinux5
OracleLinux6

References

Timeline

Published
Last Modified
Status
Analyzed

Frequently Asked Questions

What is CVE-2014-3153?
The futex_requeue function in kernel/futex.c in the Linux kernel through 3.14.5 does not ensure that calls have two different futex addresses, which allows local users to gain privileges via a crafted FUTEX_REQUEUE command that facilitates unsafe waiter modification.
How severe is CVE-2014-3153?
CVE-2014-3153 has a CVSS score of 7.8/10 (HIGH severity). The EPSS model estimates a 37.23% probability of exploitation in the next 30 days. This vulnerability is listed in CISA's Known Exploited Vulnerabilities catalog.
How do I fix CVE-2014-3153?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2014-3153?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST