The futex_requeue function in kernel/futex.c in the Linux kernel through 3.14.5 does not ensure that calls have two different futex addresses, which allows local users to gain privileges via a crafted FUTEX_REQUEUE command that facilitates unsafe waiter modification.
Conclusion & alert: CVE-2014-3153 is rated Critical Active Threat (85.6/100): CVSS High severity, with high exploitation likelihood (EPSS 37.23%, 98th percentile). Core evidence: CISA KEV confirms active exploitation (added 2022-05-25) affecting Linux / Kernel. Unauthenticated remote administrative access may be possible. Mandatory action: The CISA remediation deadline has passed—treat as an emergency patch priority.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
: Linux Kernel Privilege Escalation Vulnerability · CISA KEV detail
: 2022-05-25
: 2022-06-15
: Apply updates per vendor instructions.
| EDB-ID | Source | Kind | Published | Link |
|---|---|---|---|---|
| 35370 | exploit_db | edb | 2014-11-25 | Exploit-DB ↗ |
| — | nvd_ref | exploit_tag | Exploit-DB ↗ | |
| — | nvd_ref | exploit_tag | Exploit-DB ↗ |
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 75.33% | 37.23% | -38.10% |
| 2 | 2026-06-06 | 71.36% | 75.33% | +3.97% |
| 3 | 2026-06-04 | — | 71.36% | — |
Full EPSS history (70 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 7.8 | 3.1 | HIGH |
|
1.8 | 5.9 | [email protected] |
| 7.8 | 3.1 | HIGH |
|
1.8 | 5.9 | 134c704f-9b21-4f2e-91b3-4a467353bcc0 |
| 7.2 | 2.0 | HIGH |
|
3.9 | 10.0 | [email protected] |
| vendor | priority | summary | link |
|---|---|---|---|
debian
|
not yet assigned | CVE-2014-3153 not yet assigned priority: Debian including 1 source packages (linux), 5 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 5. | https://security-tracker.debian.org/tracker/CVE-2014-3153 |
redhat
|
high | — | https://access.redhat.com/security/cve/CVE-2014-3153 |
ubuntu
|
high | CVE-2014-3153 high priority: Ubuntu including 30 source packages (linux, linux-armadaxp, …), 295 status rows across 11 suites (lucid, precise, saucy, trusty, upstream, utopic, vivid, wily, xenial, yakkety, zesty): DNE 205, released 41, not-affected 35, ignored 14. | https://ubuntu.com/security/CVE-2014-3153 |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| linux | linux_kernel | < 3.2.60 | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
| linux | linux_kernel | >= 3.3, < 3.4.92 | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
| linux | linux_kernel | >= 3.5, < 3.10.42 | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
| linux | linux_kernel | >= 3.11, < 3.12.22 | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
| linux | linux_kernel | >= 3.13, < 3.14.6 | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
| redhat | enterprise_linux_server_aus | 6.2 | cpe:2.3:o:redhat:enterprise_linux_server_aus:6.2:*:*:*:*:*:*:* |
| opensuse | opensuse | 11.4 | cpe:2.3:o:opensuse:opensuse:11.4:*:*:*:*:*:*:* |
| suse | linux_enterprise_desktop | 11 | cpe:2.3:o:suse:linux_enterprise_desktop:11:sp3:*:*:*:*:*:* |
| suse | linux_enterprise_high_availability_extension | 11 | cpe:2.3:o:suse:linux_enterprise_high_availability_extension:11:sp3:*:*:*:*:*:* |
| suse | linux_enterprise_real_time_extension | 11 | cpe:2.3:o:suse:linux_enterprise_real_time_extension:11:sp3:*:*:*:*:*:* |
| suse | linux_enterprise_server | 11 | cpe:2.3:o:suse:linux_enterprise_server:11:-:*:*:*:*:*:* |
| suse | linux_enterprise_server | 11 | cpe:2.3:o:suse:linux_enterprise_server:11:sp2:*:*:ltss:*:*:* |
| suse | linux_enterprise_server | 11 | cpe:2.3:o:suse:linux_enterprise_server:11:sp3:*:*:*:-:*:* |
| suse | linux_enterprise_server | 11 | cpe:2.3:o:suse:linux_enterprise_server:11:sp3:*:*:*:vmware:*:* |
| canonical | ubuntu_linux | 12.04 | cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:-:*:*:* |
| canonical | ubuntu_linux | 14.04 | cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:esm:*:*:* |
| oracle | linux | 5 | cpe:2.3:o:oracle:linux:5:-:*:*:*:*:*:* |
| oracle | linux | 6 | cpe:2.3:o:oracle:linux:6:-:*:*:*:*:*:* |