The futex_requeue function in kernel/futex.c in the Linux kernel through 3.14.5 does not ensure that calls have two different futex addresses, which allows local users to gain privileges via a crafted FUTEX_REQUEUE command that facilitates unsafe waiter modification.
2014-06-07T14:55:27.240
2025-04-12T10:46:40.837
Deferred
CVSSv3.1: 7.8 (HIGH)
AV:L/AC:L/Au:N/C:C/I:C/A:C
3.9
10.0
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | linux | linux_kernel | < 3.2.60 | Yes |
Operating System | linux | linux_kernel | < 3.4.92 | Yes |
Operating System | linux | linux_kernel | < 3.10.42 | Yes |
Operating System | linux | linux_kernel | < 3.12.22 | Yes |
Operating System | linux | linux_kernel | < 3.14.6 | Yes |
Operating System | redhat | enterprise_linux_server_aus | 6.2 | Yes |
Operating System | opensuse | opensuse | 11.4 | Yes |
Operating System | suse | linux_enterprise_desktop | 11 | Yes |
Operating System | suse | linux_enterprise_high_availability_extension | 11 | Yes |
Operating System | suse | linux_enterprise_real_time_extension | 11 | Yes |
Operating System | suse | linux_enterprise_server | 11 | Yes |
Operating System | suse | linux_enterprise_server | 11 | Yes |
Operating System | suse | linux_enterprise_server | 11 | Yes |
Operating System | suse | linux_enterprise_server | 11 | Yes |
Operating System | canonical | ubuntu_linux | 12.04 | Yes |
Operating System | canonical | ubuntu_linux | 14.04 | Yes |
Operating System | oracle | linux | 5 | Yes |
Operating System | oracle | linux | 6 | Yes |