CVE-2014-3153

HIGH KEV RANSOMWARE

Linux Kernel <=3.14.5 - Privilege Escalation

Title source: llm

Description

The futex_requeue function in kernel/futex.c in the Linux kernel through 3.14.5 does not ensure that calls have two different futex addresses, which allows local users to gain privileges via a crafted FUTEX_REQUEUE command that facilitates unsafe waiter modification.

Exploits (12)

exploitdb WORKING POC
by Kaiqu Chen · clocallinux
https://www.exploit-db.com/exploits/35370
nomisec WORKING POC 123 stars
by timwr · local
https://github.com/timwr/CVE-2014-3153
nomisec WORKING POC 46 stars
by geekben · local
https://github.com/geekben/towelroot
nomisec WORKING POC 19 stars
by android-rooting-tools · remote
https://github.com/android-rooting-tools/libfutex_exploit
nomisec WORKING POC 18 stars
by lieanu · local
https://github.com/lieanu/CVE-2014-3153
nomisec WORKING POC 16 stars
by dangtunguyen · local
https://github.com/dangtunguyen/TowelRoot
nomisec WORKING POC 13 stars
by elongl · local
https://github.com/elongl/CVE-2014-3153
nomisec WORKING POC 5 stars
by zerodavinci · remote
https://github.com/zerodavinci/CVE-2014-3153-exploit
nomisec WORKING POC
by c4mx · poc
https://github.com/c4mx/Linux-kernel-code-injection_CVE-2014-3153
nomisec WORKING POC
by c3c · remote
https://github.com/c3c/CVE-2014-3153
metasploit WORKING POC EXCELLENT
by Pinkie Pie, geohot, timwr · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/android/local/futex_requeue.rb

References (40)

... and 20 more

Scores

CVSS v3 7.8
EPSS 0.6889
EPSS Percentile 98.6%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CISA KEV 2022-05-25
VulnCheck KEV 2015-07-21
InTheWild.io 2014-06-07
ENISA EUVD EUVD-2014-3171
Ransomware Use Confirmed
Status published
Products (11)
canonical/ubuntu_linux 12.04
canonical/ubuntu_linux 14.04
linux/linux_kernel < 3.2.60
opensuse/opensuse 11.4
oracle/linux 5
oracle/linux 6
redhat/enterprise_linux_server_aus 6.2
suse/linux_enterprise_desktop 11 sp3
suse/linux_enterprise_high_availability_extension 11 sp3
suse/linux_enterprise_real_time_extension 11 sp3
... and 1 more
Published Jun 07, 2014
KEV Added May 25, 2022
Tracked Since Feb 18, 2026