Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2014-3153

90
FAUCET Score

CVE-2014-3153 is a local privilege escalation vulnerability in the futex_requeue function of the Linux kernel, affecting various distributions including Canonical, Red Hat, and SUSE. This flaw allows local users to gain elevated privileges by manipulating futex addresses, leading to unsafe waiter modification. With a CVSS score of 7.8 (High), it presents a significant risk due to its low attack complexity and full impact on confidentiality, integrity, and availability. The vulnerability has been actively exploited, notably via the "Towelroot" exploit, with publicly available exploit code in Metasploit and ExploitDB, and has garnered extensive community discussion and media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
< 3.2.60CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 3.3, < 3.4.92CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 3.5, < 3.10.42CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 3.11, < 3.12.22CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 3.13, < 3.14.6CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.8HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
37.23%
Probability of exploitation in next 30 days
EPSS Percentile
98.4%
Percentile rank of EPSS score among Peer Group
As of 2026-07-25
Model: v2026.06.15
Added to KEV · May 25, 2022
Metasploit: Android 'Towelroot' Futex Requeue Kernel Exploit · May 3, 2014
ExploitDB: EDB-35370 · Nov 25, 2014
This CVE's current EPSS score of 0.3723 is in the 100th percentile among its peer group of 16,985 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (6)

github_advisorypatch availablevia nvd_reference
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 6Fixed in: kernel-0:2.6.32-431.20.3.el6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 6.2 Advanced Update SupportFixed in: kernel-0:2.6.32-220.52.1.el6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 6.4 Extended Update SupportFixed in: kernel-0:2.6.32-358.46.1.el6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: kernel-0:3.10.0-123.4.2.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise MRG 2Fixed in: kernel-rt-0:3.10.33-rt32.43.el6rt
View patch

Vendor Advisories (1)

redhatCVE-2014-3153Important

kernel: futex: pi futexes requeue issue

Jun 4, 2014

References

cisa.gov / known-exploited-vulnerabilities-catalog
US Government Resource
git.kernel.org
Broken Link
linux.oracle.com / errata/ELSA-2014-0771.html
Third Party Advisory
linux.oracle.com / errata/ELSA-2014-3037.html
Third Party Advisory
linux.oracle.com / errata/ELSA-2014-3038.html
Third Party Advisory
linux.oracle.com / errata/ELSA-2014-3039.html
Third Party Advisory
lists.opensuse.org / opensuse-security-announce/2014-06/msg00014.html
Mailing ListThird Party Advisory
lists.opensuse.org / opensuse-security-announce/2014-06/msg00018.html
Mailing ListThird Party Advisory
lists.opensuse.org / opensuse-security-announce/2014-06/msg00025.html
Mailing ListThird Party Advisory
lists.opensuse.org / opensuse-security-announce/2014-07/msg00006.html
Mailing ListThird Party Advisory
lists.opensuse.org / opensuse-security-announce/2014-10/msg00006.html
Mailing ListThird Party Advisory
lists.opensuse.org / opensuse-security-announce/2014-10/msg00007.html
Mailing ListThird Party Advisory
openwall.com / lists/oss-security/2014/06/05/24
Mailing List
openwall.com / lists/oss-security/2014/06/06/20
Mailing List
rhn.redhat.com / errata/RHSA-2014-0800.html
Third Party Advisory
bugzilla.redhat.com / show_bug.cgi
Issue TrackingThird Party Advisory
secunia.com / advisories/58500
Broken Link
secunia.com / advisories/58990
Broken Link
secunia.com / advisories/59029
Broken Link
secunia.com / advisories/59092
Broken Link
secunia.com / advisories/59153
Broken Link
secunia.com / advisories/59262
Broken Link
secunia.com / advisories/59309
Broken Link
secunia.com / advisories/59386
Broken Link
secunia.com / advisories/59599
Broken Link
elongl.github.io / exploitation/2021/01/08/cve-2014-3153.html
Exploit
github.com / elongl/CVE-2014-3153
Third Party Advisory
github.com / torvalds/linux/commit/e9c243a5a6de0be8e584c604d353412584b592f8
Patch
git.kernel.org / cgit/linux/kernel/git/torvalds/linux.git/commit
Mailing ListPatch
git.kernel.org / cgit/linux/kernel/git/torvalds/linux.git/commit
Mailing ListPatch
git.kernel.org / cgit/linux/kernel/git/torvalds/linux.git/commit
Mailing ListPatch
openwall.com / lists/oss-security/2021/02/01/4
Mailing List
debian.org / security/2014/dsa-2949
Exploit
exploit-db.com / exploits/35370
Third Party AdvisoryVDB Entry
openwall.com / lists/oss-security/2014/06/05/22
Mailing List
openwall.com / lists/oss-security/2021/02/01/4
Mailing List
securityfocus.com / bid/67906
Broken LinkThird Party AdvisoryVDB Entry
securitytracker.com / id/1030451
Broken LinkThird Party AdvisoryVDB Entry
ubuntu.com / usn/USN-2237-1
Third Party Advisory
ubuntu.com / usn/USN-2240-1
Third Party Advisory