peter bassill · operator
$ cve CVE-2014-3153 JSON

CVE-2014-3153 KEV EXPLOIT

7.8
HIGH · CVSS 3.1 · EPSS 37.2% (pctl 98)

Patch first

On CISA KEV — known exploited in the wild, due 2022-06-15.

Description

The futex_requeue function in kernel/futex.c in the Linux kernel through 3.14.5 does not ensure that calls have two different futex addresses, which allows local users to gain privileges via a crafted FUTEX_REQUEUE command that facilitates unsafe waiter modification.

Scoring

CVSS7.8 (HIGH, v3.1)
VectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS37.23% — more likely to be exploited than 98% of all CVEs
On CISA KEVyes — remediate by 2022-06-15
Public exploityes
Published2014-06-07
Last modified2026-06-17

CISA KEV

NameLinux Kernel Privilege Escalation Vulnerability
Added2022-05-25
Due2022-06-15
Vendor / productLinux / Kernel
Ransomware usenone reported

Affected (9)

VendorProduct
canonicalubuntu linux
linuxlinux kernel
opensuseopensuse
oraclelinux
redhatenterprise linux server aus
suselinux enterprise desktop
suselinux enterprise high availability extension
suselinux enterprise real time extension
suselinux enterprise server

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD