CVE-2014-3153 is a local privilege escalation vulnerability in the futex_requeue function of the Linux kernel, affecting various distributions including Canonical, Red Hat, and SUSE. This flaw allows local users to gain elevated privileges by manipulating futex addresses, leading to unsafe waiter modification. With a CVSS score of 7.8 (High), it presents a significant risk due to its low attack complexity and full impact on confidentiality, integrity, and availability. The vulnerability has been actively exploited, notably via the "Towelroot" exploit, with publicly available exploit code in Metasploit and ExploitDB, and has garnered extensive community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 3.2.60CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 3.3, < 3.4.92CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 3.5, < 3.10.42CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 3.11, < 3.12.22CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 3.13, < 3.14.6CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.