The futex_requeue function in kernel/futex.c in the Linux kernel through 3.14.5 does not ensure that calls have two different futex addresses, which allows local users to gain privileges via a crafted FUTEX_REQUEUE command that facilitates unsafe waiter modification.
Metrics
Affected Vendors & Products
Advisories
Source | ID | Title |
---|---|---|
![]() |
DSA-2949-1 | linux security update |
![]() |
DSA-2950-1 | openssl security update |
![]() |
USN-2233-1 | Linux kernel vulnerabilities |
![]() |
USN-2234-1 | Linux kernel (EC2) vulnerabilities |
![]() |
USN-2235-1 | Linux kernel vulnerabilities |
![]() |
USN-2236-1 | Linux kernel (OMAP4) vulnerabilities |
![]() |
USN-2237-1 | Linux kernel (Quantal HWE) vulnerability |
![]() |
USN-2238-1 | Linux kernel (Raring HWE) vulnerabilities |
![]() |
USN-2239-1 | Linux kernel (Saucy HWE) vulnerabilities |
![]() |
USN-2240-1 | Linux kernel vulnerabilities |
![]() |
USN-2241-1 | Linux kernel vulnerabilities |
![]() |
USN-2260-1 | Linux kernel (Trusty HWE) vulnerabilities |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Mon, 03 Feb 2025 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
kev
|
Tue, 13 Aug 2024 23:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
References |
|

Status: PUBLISHED
Assigner: Chrome
Published:
Updated: 2025-07-30T01:46:50.582Z
Reserved: 2014-05-03T00:00:00.000Z
Link: CVE-2014-3153

Updated: 2024-08-06T10:35:56.633Z

Status : Deferred
Published: 2014-06-07T14:55:27.240
Modified: 2025-04-12T10:46:40.837
Link: CVE-2014-3153


No data.