Vulnerability record · CVE-2014-3153 · published 7 June 2014
CVE-2014-3153: Linux Kernel futex_requeue Local Privilege Escalation
Linux · Linux Kernel
The futex_requeue function in kernel/futex.c in the Linux kernel through 3.14.5 fails to verify that a FUTEX_REQUEUE call supplies two different futex addresses, allowing unsafe waiter modification. A local user can exploit this to corrupt kernel futex state and escalate privileges. It matters because the flaw is reachable by any local account and affects a broad set of Linux distributions and enterprise kernels.
Description
The futex_requeue function in kernel/futex.c in the Linux kernel through 3.14.5 does not ensure that calls have two different futex addresses, which allows local users to gain privileges via a crafted FUTEX_REQUEUE command that facilitates unsafe waiter modification.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityThe flaw gives local users full root on unpatched kernels, is in CISA KEV, and has a high EPSS score, but it requires local access rather than being remotely reachable.
What it is
The futex_requeue function in kernel/futex.c in the Linux kernel through 3.14.5 fails to verify that a FUTEX_REQUEUE call supplies two different futex addresses, allowing unsafe waiter modification. A local user can exploit this to corrupt kernel futex state and escalate privileges. It matters because the flaw is reachable by any local account and affects a broad set of Linux distributions and enterprise kernels.
Impact
An attacker with a local account gains full root privileges on the affected host, including the ability to read or modify any data and persist on the system.
Attack surface
Reached locally by invoking the futex syscall with a crafted FUTEX_REQUEUE command; the CVSS vector shows AV:L, PR:L, UI:N, so a low-privileged local account is required and no user interaction is needed.
Exploitation
CVE-2014-3153 is listed in CISA KEV (added 2022-05-25) and has an EPSS 30-day probability of 0.37233 (98.4th percentile), with public exploit references including Exploit-DB 35370 and a Debian advisory tagged Exploit.
What to do
- Apply the vendor kernel updates referenced in the Oracle, Red Hat, openSUSE, SUSE, Canonical and Debian advisories; this is the only complete fix.
- If patching cannot be done immediately, restrict local shell and interactive access to trusted users only.
- Enforce least privilege so that untrusted code does not run under accounts that can invoke futex operations on the host.
- For container or multi-tenant hosts, ensure the host kernel is patched rather than relying on container isolation alone.
Detection
- Monitor for unexpected processes gaining uid 0 or spawning shells from non-root parent processes.
- Audit local futex syscall activity for FUTEX_REQUEUE calls with identical source and destination addresses where telemetry allows.
- Watch for known exploit artifacts or binaries associated with public PoCs for this futex flaw.
- Alert on kernel oops or futex-related warnings in dmesg that coincide with privilege changes.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2014-3153 to the Known Exploited Vulnerabilities catalog on 25 May 2022 as "Linux Kernel Privilege Escalation Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 15 June 2022.
Affected products
9 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2014-3153 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2014-3153), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.