CVE-2014-3153

Scores

EPSS

0.689medium68.9%
0%20%40%60%80%100%

Percentile: 68.9%

CVSS

7.8high3.x
0246810

CVSS Score: 7.8/10

All CVSS Scores

CVSS 3.x
7.8

Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CVSS 2.0
7.2

Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Description

The futex_requeue function in kernel/futex.c in the Linux kernel through 3.14.5 does not ensure that calls have two different futex addresses, which allows local users to gain privileges via a crafted FUTEX_REQUEUE command that facilitates unsafe waiter modification.

Scaner-VS 7 — a modern vulnerability management solution

Uses this database for vulnerability detection. High-speed search, cross-platform, advanced configuration audit, and flexible filtering. Suitable for organizations of any size.
Learn more about Scaner-VS 7

Sources

debiannvdredhatubuntu

Exploits

Exploit ID: 35370

Source: exploitdb

URL: https://www.exploit-db.com/exploits/35370

Exploit ID: CVE-2014-3153

Source: github-poc

URL: https://github.com/c4mx/Linux-kernel-code-injection_CVE-2014-3153

Recommendations

Source: nvd

Before applying this update, make sure all previously released erratarelevant to your system have been applied.
This update is available via the Red Hat Network. Details on how to use theRed Hat Network to apply this update are available athttps://access.redhat.com/site/articles/11258
To install kernel packages manually, use “rpm -ivh [package]”. Do not use”rpm -Uvh” as that will remove the running kernel binaries from yoursystem. You may use “rpm -e” to remove old kernels after determining thatthe new kernel functions properly on your system.

URL: http://rhn.redhat.com/errata/RHSA-2014-0800.html

Vulnerable Software (78)

Type: Configuration

Product: kernel

Operating System: rhel 6

Trait:
{  "fixed": "2.6.32-431.20.3.el6"}

Source: redhat

Type: Configuration

Product: kernel

Operating System: rhel 6.2

Trait:
{  "fixed": "2.6.32-220.52.1.el6"}

Source: redhat

Type: Configuration

Product: kernel

Operating System: rhel 6.4

Trait:
{  "fixed": "2.6.32-358.46.1.el6"}

Source: redhat

Type: Configuration

Product: kernel

Operating System: rhel 7

Trait:
{  "fixed": "3.10.0-123.4.2.el7"}

Source: redhat

Type: Configuration

Product: kernel-doc-un

Operating System: altlinux

Trait:
{  "fixed": "1:3.14.5-alt2"}

Source: redhat

Type: Configuration

Product: kernel-headers-modules-un-def

Operating System: altlinux

Trait:
{  "fixed": "1:3.14.5-alt2"}

Source: redhat

Type: Configuration

Product: kernel-headers-un-def

Operating System: altlinux

Trait:
{  "fixed": "1:3.14.5-alt2"}

Source: redhat

Type: Configuration

Product: kernel-image-domU-un-def

Operating System: altlinux

Trait:
{  "fixed": "1:3.14.5-alt2"}

Source: redhat

Type: Configuration

Product: kernel-image-un-def

Operating System: altlinux

Trait:
{  "fixed": "1:3.14.5-alt2"}

Source: redhat

Type: Configuration

Product: kernel-modules-drm-nouveau-un-def

Operating System: altlinux

Trait:
{  "fixed": "1:3.14.5-alt2"}

Source: redhat

Type: Configuration

Product: kernel-modules-drm-radeon-un-def

Operating System: altlinux

Trait:
{  "fixed": "1:3.14.5-alt2"}

Source: redhat

Type: Configuration

Product: kernel-modules-drm-un-def

Operating System: altlinux

Trait:
{  "fixed": "1:3.14.5-alt2"}

Source: redhat

Type: Configuration

Product: kernel-modules-ide-un-def

Operating System: altlinux

Trait:
{  "fixed": "1:3.14.5-alt2"}

Source: redhat

Type: Configuration

Product: kernel-modules-kvm-un-def

Operating System: altlinux

Trait:
{  "fixed": "1:3.14.5-alt2"}

Source: redhat

Type: Configuration

Product: kernel-modules-staging-un-def

Operating System: altlinux

Trait:
{  "fixed": "1:3.14.5-alt2"}

Source: redhat

Type: Configuration

Product: kernel-modules-v4l-un-def

Operating System: altlinux

Trait:
{  "fixed": "1:3.14.5-alt2"}

Source: redhat

Type: Configuration

Product: kernel-rt

Operating System: rhel

Trait:
{  "fixed": "3.10.33-rt32.43.el6rt"}

Source: redhat

Type: Configuration

Product: linux

Operating System: ubuntu trusty 14.04

Trait:
{  "fixed": "3.13.0-29.53"}

Source: ubuntu

Type: Configuration

Product: linux

Operating System: ubuntu utopic 14.10

Trait:
{  "unaffected": true}

Source: ubuntu

Type: Configuration

Product: linux

Operating System: ubuntu xenial 16.04

Trait:
{  "unaffected": true}

Source: ubuntu