CVE-2014-3153: Linux Kernel Privilege Escalation Vulnerability
High severity, CVSS 7.8. Actively exploited: in CISA KEV since 2022-05-25. EPSS: 37.2% chance of exploitation in the next 30 days.
The futex_requeue function in kernel/futex.c in the Linux kernel through 3.14.5 does not ensure that calls have two different futex addresses, which allows local users to gain privileges via a crafted FUTEX_REQUEUE command that facilitates unsafe waiter modification.
Affected products
- Canonical Ubuntu Linux: version 12.04 only; version 14.04 only
- Linux Linux Kernel: before 3.2.60 (fixed in 3.2.60); from 3.3, before 3.4.92 (fixed in 3.4.92); from 3.5, before 3.10.42 (fixed in 3.10.42); from 3.11, before 3.12.22 (fixed in 3.12.22); from 3.13, before 3.14.6 (fixed in 3.14.6)
- Opensuse Opensuse: version 11.4 only
- Oracle Linux: version 5 only; version 6 only
- Red Hat Enterprise Linux Server Aus: version 6.2 only
- Suse Linux Enterprise Desktop: version 11 only
- Suse Linux Enterprise High Availability Extension: version 11 only
- Suse Linux Enterprise Real Time Extension: version 11 only
- Suse Linux Enterprise Server: version 11 only
Published 2014-06-07. Last modified 2026-06-17.