← Vulnerability feed

Vulnerability record · CVE-2014-3153 · published 7 June 2014

CVE-2014-3153: Linux Kernel futex_requeue Local Privilege Escalation

Linux · Linux Kernel

The futex_requeue function in kernel/futex.c in the Linux kernel through 3.14.5 fails to verify that a FUTEX_REQUEUE call supplies two different futex addresses, allowing unsafe waiter modification. A local user can exploit this to corrupt kernel futex state and escalate privileges. It matters because the flaw is reachable by any local account and affects a broad set of Linux distributions and enterprise kernels.

7.8 CVSS 3.1 High CISA KEV since 25 May 2022 EPSS 37% · top 1.5%
7.8CVSS 3.1 base score, v2 7.2
37%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
9Affected product versions listed by NVD
79References, 4 tagged exploit
17 Jun 2026Last modified by NVD

Description

The futex_requeue function in kernel/futex.c in the Linux kernel through 3.14.5 does not ensure that calls have two different futex addresses, which allows local users to gain privileges via a crafted FUTEX_REQUEUE command that facilitates unsafe waiter modification.

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

high priorityThe flaw gives local users full root on unpatched kernels, is in CISA KEV, and has a high EPSS score, but it requires local access rather than being remotely reachable.

What it is

The futex_requeue function in kernel/futex.c in the Linux kernel through 3.14.5 fails to verify that a FUTEX_REQUEUE call supplies two different futex addresses, allowing unsafe waiter modification. A local user can exploit this to corrupt kernel futex state and escalate privileges. It matters because the flaw is reachable by any local account and affects a broad set of Linux distributions and enterprise kernels.

Impact

An attacker with a local account gains full root privileges on the affected host, including the ability to read or modify any data and persist on the system.

Attack surface

Reached locally by invoking the futex syscall with a crafted FUTEX_REQUEUE command; the CVSS vector shows AV:L, PR:L, UI:N, so a low-privileged local account is required and no user interaction is needed.

Exploitation

CVE-2014-3153 is listed in CISA KEV (added 2022-05-25) and has an EPSS 30-day probability of 0.37233 (98.4th percentile), with public exploit references including Exploit-DB 35370 and a Debian advisory tagged Exploit.

What to do

  • Apply the vendor kernel updates referenced in the Oracle, Red Hat, openSUSE, SUSE, Canonical and Debian advisories; this is the only complete fix.
  • If patching cannot be done immediately, restrict local shell and interactive access to trusted users only.
  • Enforce least privilege so that untrusted code does not run under accounts that can invoke futex operations on the host.
  • For container or multi-tenant hosts, ensure the host kernel is patched rather than relying on container isolation alone.

Detection

  • Monitor for unexpected processes gaining uid 0 or spawning shells from non-root parent processes.
  • Audit local futex syscall activity for FUTEX_REQUEUE calls with identical source and destination addresses where telemetry allows.
  • Watch for known exploit artifacts or binaries associated with public PoCs for this futex flaw.
  • Alert on kernel oops or futex-related warnings in dmesg that coincide with privilege changes.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2014-3153 to the Known Exploited Vulnerabilities catalog on 25 May 2022 as "Linux Kernel Privilege Escalation Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 15 June 2022.

Affected products

9 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=e9c243a5a6de0be8e584c604d353412584b592f8 Broken Link
http://linux.oracle.com/errata/ELSA-2014-0771.html Third Party Advisory
http://linux.oracle.com/errata/ELSA-2014-3037.html Third Party Advisory
http://linux.oracle.com/errata/ELSA-2014-3038.html Third Party Advisory
http://linux.oracle.com/errata/ELSA-2014-3039.html Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2014-06/msg00014.html Mailing ListThird Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2014-06/msg00018.html Mailing ListThird Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2014-06/msg00025.html Mailing ListThird Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2014-07/msg00006.html Mailing ListThird Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2014-10/msg00006.html Mailing ListThird Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2014-10/msg00007.html Mailing ListThird Party Advisory
http://openwall.com/lists/oss-security/2014/06/05/24 Mailing List
http://openwall.com/lists/oss-security/2014/06/06/20 Mailing List
http://rhn.redhat.com/errata/RHSA-2014-0800.html Third Party Advisory
http://secunia.com/advisories/58500 Broken Link
http://secunia.com/advisories/58990 Broken Link
http://secunia.com/advisories/59029 Broken Link
http://secunia.com/advisories/59092 Broken Link
http://secunia.com/advisories/59153 Broken Link
http://secunia.com/advisories/59262 Broken Link
http://secunia.com/advisories/59309 Broken Link
http://secunia.com/advisories/59386 Broken Link
http://secunia.com/advisories/59599 Broken Link
http://www.debian.org/security/2014/dsa-2949 Exploit
http://www.exploit-db.com/exploits/35370 Third Party AdvisoryVDB Entry
http://www.openwall.com/lists/oss-security/2014/06/05/22 Mailing List
http://www.openwall.com/lists/oss-security/2021/02/01/4 Mailing List
http://www.securityfocus.com/bid/67906 Broken LinkThird Party AdvisoryVDB Entry
http://www.securitytracker.com/id/1030451 Broken LinkThird Party AdvisoryVDB Entry
http://www.ubuntu.com/usn/USN-2237-1 Third Party Advisory
http://www.ubuntu.com/usn/USN-2240-1 Third Party Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=1103626 Issue TrackingThird Party Advisory
https://elongl.github.io/exploitation/2021/01/08/cve-2014-3153.html Exploit
https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=13fbca4c6ecd96ec1a1cfa2e4f2ce191fe928a5e Mailing ListPatch
https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=54a217887a7b658e2650c3feff22756ab80c7339 Mailing ListPatch
https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=b3eaa9fc5cd0a4d74b18f6b8dc617aeaf1873270 Mailing ListPatch
https://github.com/elongl/CVE-2014-3153 Third Party Advisory
https://github.com/torvalds/linux/commit/e9c243a5a6de0be8e584c604d353412584b592f8 Patch
https://www.openwall.com/lists/oss-security/2021/02/01/4 Mailing List
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=e9c243a5a6de0be8e584c604d353412584b592f8 Broken Link

Track CVE-2014-3153 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2025-39682Linux kernel TLS zero-length record handling flaw on rx_listThe Linux kernel TLS receive path mishandles zero-length records that arrive from the rx_list, breaking the assumption that a record type change cann…KEVEPSS 2.9%analysed9.8CVE-2020-11651SaltStack Salt master authentication bypass in ClearFuncsSaltStack Salt before 2019.2.4 and 3000 before 3000.2 fails to properly validate method calls in the salt-master ClearFuncs class, allowing remote un…KEVEPSS 97%analysed9.8CVE-2020-7247OpenSMTPD MAIL FROM command injection allows remote root code executionOpenSMTPD 6.6, as shipped in OpenBSD 6.6 and other products, mishandles input validation in smtp_mailaddr in smtp_session.c, returning an incorrect v…KEVEPSS 99%analysed9.8CVE-2019-5544OpenSLP heap out-of-bounds write in VMware ESXi and Horizon DaaSOpenSLP as shipped in VMware ESXi and Horizon DaaS contains a heap overwrite (out-of-bounds write) flaw. VMware rates it Critical with a maximum CVSS…KEVEPSS 97%analysed9.8CVE-2019-11043PHP-FPM buffer overflow enables remote code executionPHP-FPM in certain configurations writes past allocated buffers into FCGI protocol data space, an out-of-bounds write (CWE-787, CWE-120). It affects …KEVEPSS 100%analysed9.8CVE-2019-16928Exim heap buffer overflow in string_vformat via long EHLO commandExim 4.92 through 4.92.2 contains a heap-based buffer overflow in string_vformat in string.c triggered by a long EHLO command, allowing remote code e…KEVEPSS 42%analysed9.8CVE-2019-10149Exim MTA improper recipient validation leads to remote command executionExim versions 4.87 through 4.91 fail to properly validate recipient addresses in the deliver_message() function in /src/deliver.c, allowing command i…KEVEPSS 100%analysed9.8CVE-2018-6789Exim SMTP base64d buffer overflow allows remote code executionExim before 4.90.1 contains a buffer overflow in the base64d function of its SMTP listener. A handcrafted message can trigger the overflow, and the f…KEVEPSS 82%analysed

Source: NIST National Vulnerability Database (record CVE-2014-3153), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.