kernel: futex: pi futexes requeue issue
Published Jun 7, 2014 ·Due Jun 15, 2022
7.8
HIGHCVSS 3.1
EPSS 37.23%
Description
The futex_requeue function in kernel/futex.c in the Linux kernel through 3.14.5 does not ensure that calls have two different futex addresses, which allows local users to gain privileges via a crafted FUTEX_REQUEUE command that facilitates unsafe waiter modification.
Affected products
No data.
Configuration 1
- < 3.2.60
- ≥ 3.3 · < 3.4.92
- ≥ 3.5 · < 3.10.42
- ≥ 3.11 · < 3.12.22
- ≥ 3.13 · < 3.14.6
Configuration 2
- 6.2
Configuration 3
- 11.4
- 11
- 11
- 11
- 11
- 11
- 11
- 11
Configuration 4
- 12.04
- 14.04
No data.
Red Hat Enterprise Linux 6
kernel-0:2.6.32-431.20.3.el6
Fixed · RHSA-2014:0771
Red Hat Enterprise Linux 6.2 Advanced Update Support
kernel-0:2.6.32-220.52.1.el6
Fixed · RHSA-2014:0800
Red Hat Enterprise Linux 6.4 Extended Update Support
kernel-0:2.6.32-358.46.1.el6
Fixed · RHSA-2014:0900
Red Hat Enterprise Linux 7
kernel-0:3.10.0-123.4.2.el7
Fixed · RHSA-2014:0786
Red Hat Enterprise MRG 2
kernel-rt-0:3.10.33-rt32.43.el6rt
Fixed · RHSA-2014:0913
Red Hat Enterprise Linux 5
kernel
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 | kernel-0:2.6.32-431.20.3.el6 | Fixed | RHSA-2014:0771 |
| Red Hat Enterprise Linux 6.2 Advanced Update Support | kernel-0:2.6.32-220.52.1.el6 | Fixed | RHSA-2014:0800 |
| Red Hat Enterprise Linux 6.4 Extended Update Support | kernel-0:2.6.32-358.46.1.el6 | Fixed | RHSA-2014:0900 |
| Red Hat Enterprise Linux 7 | kernel-0:3.10.0-123.4.2.el7 | Fixed | RHSA-2014:0786 |
| Red Hat Enterprise MRG 2 | kernel-rt-0:3.10.33-rt32.43.el6rt | Fixed | RHSA-2014:0913 |
| Red Hat Enterprise Linux 5 | kernel | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This issue did not affect the versions of the Linux kernel packages as shipped with Red Hat Enterprise Linux 5. This issue requires local system access to be exploited. We are currently not aware of any working exploit for Red Hat Enterprise Linux 6 or Red Hat Enterprise MRG 2.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
No CVSS v3.0 score for this CVE.
AV:L/AC:L/Au:N/C:C/I:C/A:C
Date Added
May 25, 2022
Patch Due
Jun 15, 2022
Required Action
Apply updates per vendor instructions.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
ActiveAutomatable
NoTechnical Impact
TotalDecision
n/aAssessed Feb 3, 2025 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (37 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 37.23% (0.37233) | 98.48th | v5 (v2026.06.15) |
| Jun 15, 2026 | 37.23% (0.37233) | 98.32th | v5 (v2026.06.15) |
| Jun 6, 2026 | 75.33% (0.75331) | 98.91th | v4 (v2025.03.14) |
| Jun 4, 2026 | 71.36% (0.71360) | 98.74th | v4 (v2025.03.14) |
| May 26, 2026 | 68.89% (0.68892) | 98.65th | v4 (v2025.03.14) |
| May 23, 2026 | 71.36% (0.71360) | 98.74th | v4 (v2025.03.14) |
| Mar 4, 2026 | 68.89% (0.68892) | 98.59th | v4 (v2025.03.14) |
| Mar 2, 2026 | 70.11% (0.70110) | 98.66th | v4 (v2025.03.14) |
| Mar 1, 2026 | 73.28% (0.73285) | 98.78th | v4 (v2025.03.14) |
| Feb 18, 2026 | 72.19% (0.72190) | 98.72th | v4 (v2025.03.14) |
| Feb 2, 2026 | 76.04% (0.76043) | 98.89th | v4 (v2025.03.14) |
| Jan 27, 2026 | 72.58% (0.72582) | 98.73th | v4 (v2025.03.14) |
| Jan 11, 2026 | 71.36% (0.71360) | 98.67th | v4 (v2025.03.14) |
| Dec 28, 2025 | 75.33% (0.75331) | 98.83th | v4 (v2025.03.14) |
| Dec 4, 2025 | 71.76% (0.71763) | 98.67th | v4 (v2025.03.14) |
| Dec 1, 2025 | 72.87% (0.72874) | 98.72th | v4 (v2025.03.14) |
| Nov 13, 2025 | 71.36% (0.71360) | 98.65th | v4 (v2025.03.14) |
| Nov 4, 2025 | 68.89% (0.68892) | 98.55th | v4 (v2025.03.14) |
| Nov 1, 2025 | 70.11% (0.70110) | 98.61th | v4 (v2025.03.14) |
| Oct 31, 2025 | 68.89% (0.68892) | 98.55th | v4 (v2025.03.14) |
| Oct 22, 2025 | 71.36% (0.71360) | 98.64th | v4 (v2025.03.14) |
| Oct 7, 2025 | 80.51% (0.80511) | 99.09th | v4 (v2025.03.14) |
| Sep 25, 2025 | 79.18% (0.79178) | 99.04th | v4 (v2025.03.14) |
| Aug 11, 2025 | 80.51% (0.80511) | 99.09th | v4 (v2025.03.14) |
| Jul 22, 2025 | 82.58% (0.82581) | 99.17th | v4 (v2025.03.14) |
| Jul 5, 2025 | 81.44% (0.81444) | 99.12th | v4 (v2025.03.14) |
| Jun 25, 2025 | 83.51% (0.83510) | 99.21th | v4 (v2025.03.14) |
| May 5, 2025 | 82.36% (0.82357) | 99.16th | v4 (v2025.03.14) |
| Apr 19, 2025 | 85.26% (0.85258) | 99.28th | v4 (v2025.03.14) |
| Mar 17, 2025 | 86.63% (0.86625) | 99.38th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.82% (0.00820) | 82.56th | v3 (v2023.03.01) |
| Jul 3, 2024 | 0.63% (0.00628) | 79.12th | v3 (v2023.03.01) |
| Nov 8, 2023 | 0.13% (0.00129) | 47.36th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.05% (0.00052) | 18.60th | v3 (v2023.03.01) |
| Mar 6, 2023 | 2.30% (0.02302) | 81.41th | v2 (v2022.01.01) |
| Apr 1, 2022 | 2.30% (0.02302) | 79.64th | v2 (v2022.01.01) |
| Feb 4, 2022 | 2.30% (0.02302) | 58.27th | v2 (v2022.01.01) |
No CWE recorded.
References (44)
- http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=e9c243a5a6de0be8e584c604d353412584b592f8 x_refsource_CONFIRMBroken Link
- http://linux.oracle.com/errata/ELSA-2014-0771.html x_refsource_CONFIRMThird Party Advisory
- http://linux.oracle.com/errata/ELSA-2014-3037.html x_refsource_CONFIRMThird Party Advisory
- http://linux.oracle.com/errata/ELSA-2014-3038.html x_refsource_CONFIRMThird Party Advisory
- http://linux.oracle.com/errata/ELSA-2014-3039.html x_refsource_CONFIRMThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2014-06/msg00014.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2014-06/msg00018.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2014-06/msg00025.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2014-07/msg00006.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2014-10/msg00006.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2014-10/msg00007.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://openwall.com/lists/oss-security/2014/06/05/24 mailing-listx_refsource_MLISTMailing List
- http://openwall.com/lists/oss-security/2014/06/06/20 mailing-listx_refsource_MLISTMailing List
- http://rhn.redhat.com/errata/RHSA-2014-0800.html vendor-advisoryx_refsource_REDHATThird Party Advisory
- http://secunia.com/advisories/58500 third-party-advisoryx_refsource_SECUNIABroken Link
- http://secunia.com/advisories/58990 third-party-advisoryx_refsource_SECUNIABroken Link
- http://secunia.com/advisories/59029 third-party-advisoryx_refsource_SECUNIABroken Link
- http://secunia.com/advisories/59092 third-party-advisoryx_refsource_SECUNIABroken Link
- http://secunia.com/advisories/59153 third-party-advisoryx_refsource_SECUNIABroken Link
- http://secunia.com/advisories/59262 third-party-advisoryx_refsource_SECUNIABroken Link
- http://secunia.com/advisories/59309 third-party-advisoryx_refsource_SECUNIABroken Link
- http://secunia.com/advisories/59386 third-party-advisoryx_refsource_SECUNIABroken Link
- http://secunia.com/advisories/59599 third-party-advisoryx_refsource_SECUNIABroken Link
- http://www.debian.org/security/2014/dsa-2949 vendor-advisoryx_refsource_DEBIANExploit
- http://www.exploit-db.com/exploits/35370 exploitx_refsource_EXPLOIT-DBThird Party AdvisoryVDB Entry
- http://www.openwall.com/lists/oss-security/2014/06/05/22 mailing-listx_refsource_MLISTMailing List
- http://www.openwall.com/lists/oss-security/2021/02/01/4 mailing-listx_refsource_MLISTMailing List
- http://www.securityfocus.com/bid/67906 vdb-entryx_refsource_BIDBroken LinkThird Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1030451 vdb-entryx_refsource_SECTRACKBroken LinkThird Party AdvisoryVDB Entry
- http://www.ubuntu.com/usn/USN-2237-1 vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- http://www.ubuntu.com/usn/USN-2240-1 vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2014-3153 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1103626 x_refsource_CONFIRMIssue TrackingThird Party Advisory
- https://elongl.github.io/exploitation/2021/01/08/cve-2014-3153.html x_refsource_MISCExploit
- https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=13fbca4c6ecd96ec1a1cfa2e4f2ce191fe928a5e x_refsource_CONFIRMMailing ListPatch
- https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=54a217887a7b658e2650c3feff22756ab80c7339 x_refsource_CONFIRMMailing ListPatch
- https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=b3eaa9fc5cd0a4d74b18f6b8dc617aeaf1873270 x_refsource_CONFIRMMailing ListPatch
- https://github.com/elongl/CVE-2014-3153 x_refsource_MISCThird Party Advisory
- https://github.com/torvalds/linux/commit/e9c243a5a6de0be8e584c604d353412584b592f8 x_refsource_CONFIRMPatch
- https://nvd.nist.gov/vuln/detail/CVE-2014-3153
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2014-3153 government-resourceUS Government Resource
- https://www.cve.org/CVERecord?id=CVE-2014-3153
- https://www.openwall.com/lists/oss-security/2021/02/01/4 x_refsource_MISCMailing List
Change history (0)
No recorded changes yet.