CVE Database
/

CVE-2014-3153

Back to search

CVE-2014-3153

Published: Jun 7, 2014

Modified: Oct 22, 2025

PUBLISHED

Description

The futex_requeue function in kernel/futex.c in the Linux kernel through 3.14.5 does not ensure that calls have two different futex addresses, which allows local users to gain privileges via a crafted FUTEX_REQUEUE command that facilitates unsafe waiter modification.

VendorProductVersions

n/a

n/a

affected
n/a

References

67906
vdb-entry
x_refsource_BID
openSUSE-SU-2014:0878
vendor-advisory
x_refsource_SUSE
59029
third-party-advisory
x_refsource_SECUNIA
DSA-2949
vendor-advisory
x_refsource_DEBIAN
SUSE-SU-2014:1316
vendor-advisory
x_refsource_SUSE
SUSE-SU-2014:0796
vendor-advisory
x_refsource_SUSE
59262
third-party-advisory
x_refsource_SECUNIA
58990
third-party-advisory
x_refsource_SECUNIA
59153
third-party-advisory
x_refsource_SECUNIA
59309
third-party-advisory
x_refsource_SECUNIA
1030451
vdb-entry
x_refsource_SECTRACK
SUSE-SU-2014:0775
vendor-advisory
x_refsource_SUSE
RHSA-2014:0800
vendor-advisory
x_refsource_REDHAT
USN-2237-1
vendor-advisory
x_refsource_UBUNTU
SUSE-SU-2014:1319
vendor-advisory
x_refsource_SUSE
58500
third-party-advisory
x_refsource_SECUNIA
USN-2240-1
vendor-advisory
x_refsource_UBUNTU
59386
third-party-advisory
x_refsource_SECUNIA
35370
exploit
x_refsource_EXPLOIT-DB
59599
third-party-advisory
x_refsource_SECUNIA
SUSE-SU-2014:0837
vendor-advisory
x_refsource_SUSE
59092
third-party-advisory
x_refsource_SECUNIA

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now