CVE-2014-3153
KEVHIGH 7.8EPSS 37.2%
The futex_requeue function in kernel/futex.c in the Linux kernel through 3.14.5 does not ensure that calls have two different futex addresses, which allows local users to gain privileges via a crafted FUTEX_REQUEUE command that facilitates unsafe waiter modification.
- CVSS v3.1
- 7.8 HIGH
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H - CVSS v3.1
- 7.8 HIGH
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H - CVSS v2.0
- 7.2 HIGH
AV:L/AC:L/Au:N/C:C/I:C/A:C - EPSS
- 37.23% chance of exploitation in the next 30 days, 98th percentile
- CISA KEV
- added 2022-05-25
- Published
- 2014-06-07
- Updated
- 2025-10-22
Proof-of-concept exploits (11)
- http://www.exploit-db.com/exploits/35370
- https://elongl.github.io/exploitation/2021/01/08/cve-2014-3153.html
- android-rooting-tools/libfutex_exploit19★ · 2015-10-07
- c3c/CVE-2014-31530★ · 2015-09-04
- c4mx/Linux-kernel-code-injection_CVE-2014-31530★ · 2022-02-01
- elongl/CVE-2014-315313★ · 2021-01-16
- geekben/towelroot46★ · 2014-10-25
- lieanu/CVE-2014-315318★ · 2015-01-24
- sin4ts/CVE2014-31531★ · 2016-05-15
- timwr/CVE-2014-3153124★ · 2017-04-25
- zerodavinci/CVE-2014-3153-exploit5★ · 2016-03-08