CVE-2014-3153
CVSS v3.1
7.8 (High)
CVSS v2.0
7.2 (High)
EPSS
0.63 % (79th)
Affected Products
9
Advisories
57
NVD Status
Analyzed
The futex_requeue function in kernel/futex.c in the Linux kernel through 3.14.5 does not ensure that calls have two different futex addresses, which allows local users to gain privileges via a crafted FUTEX_REQUEUE command that facilitates unsafe waiter modification.
Weaknesses
- CVE Status
- PUBLISHED
- NVD Status
- Analyzed
- CNA
- Chrome
- Published Date
-
2014-06-07 14:55:27
(10 years ago) - Updated Date
-
2024-07-02 12:17:50
(2 months ago)
Linux Kernel Privilege Escalation Vulnerability (CISA - Known Exploited Vulnerabilities Catalog)
- Description
- The futex_requeue function in kernel/futex.c in Linux kernel does not ensure that calls have two different futex addresses, which allows local users to gain privileges.
- Required Action
- Apply updates per vendor instructions.
- Known to be Used in Ransomware Campaigns
- Unknown
- Notes
- https://nvd.nist.gov/vuln/detail/CVE-2014-3153
- Vendor
- Linux
- Product
- Kernel
- In CISA Catalog from
-
2022-05-25
(2 years ago) - Due Date
-
2022-06-15
(2 years ago)
Affected Products
Loading...
Loading...
Configuration #1
|
Configuration #2
|
Configuration #3
|
Configuration #4
|
Configuration #5
|
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...