The futex_requeue function in kernel/futex.c in the Linux kernel through 3.14.5 does not ensure that calls have two different futex addresses, which allows local users to gain privileges via a crafted FUTEX_REQUEUE command that facilitates unsafe waiter modification.
CVE-2014-3153
Score elevated to 9.0 because this CVE is listed on the CISA Known Exploited Vulnerabilities catalog (added 2022-05-25), indicating real-world exploitation has been confirmed by US federal agencies. NVD baseline CVSS 7.8 retained for reference. Confidence: HIGH.
- Actively exploited in the wild (CISA-KEV)
A fix is available — apply it.
- CVSS v3
- 7.8
- EG Score
- 9.0(high)
- EPSS
- 98.4%
- KEV
- ⚠ Exploited
Published
June 7, 2014
Last Modified
April 21, 2026
Advisory Details (4)
Auto-updated May 19, 2026Vendor Advisories for CVE-2014-3153(4)
These vendors published their own advisory mentioning this CVE — often with vendor-specific remediation steps + affected product lists not in NVD.
- RHSA-2014:0900Red Hat Product SecurityHigh
Red Hat Security Advisory: kernel security and bug fix update
- RHSA-2014:0800Red Hat Product SecurityHigh
Red Hat Security Advisory: kernel security update
- RHSA-2014:0786Red Hat Product SecurityHigh
Red Hat Security Advisory: kernel security, bug fix, and enhancement update
- RHSA-2014:0771Red Hat Product SecurityHigh
Red Hat Security Advisory: kernel security and bug fix update
Patch Availability(15)
Patches are aggregated from vendor advisories (Red Hat, Microsoft, Cisco, GitHub) and package ecosystems (OSV, GHSA). Multiple rows for the same upstream release have been deduplicated.
Weakness Classification(1)
MITRE Common Weakness Enumeration — the root-cause categories this CVE belongs to.
Additional Vendor Advisories
(11)
Vendors that published advisories for this CVE beyond the curated set above. Broader coverage but minimal per-row detail — click through for the original advisory.
- Red HatRHSA-2014:0913IMPORTANT2014-06-04
RHSA-2014:0913 — Important
- UbuntuUSN-2233-1HIGH
Linux kernel vulnerabilities
- UbuntuUSN-2234-1HIGH
Linux kernel (EC2) vulnerabilities
- UbuntuUSN-2235-1HIGH
Linux kernel vulnerabilities
- UbuntuUSN-2236-1HIGH
Linux kernel (OMAP4) vulnerabilities
- UbuntuUSN-2237-1HIGH
Linux kernel (Quantal HWE) vulnerability
- UbuntuUSN-2238-1HIGH
Linux kernel (Raring HWE) vulnerabilities
- UbuntuUSN-2239-1HIGH
Linux kernel (Saucy HWE) vulnerabilities
- UbuntuUSN-2240-1HIGH
Linux kernel vulnerabilities
- UbuntuUSN-2241-1HIGH
Linux kernel vulnerabilities
- UbuntuUSN-2260-1HIGH
Linux kernel (Trusty HWE) vulnerabilities
Data Freshness Timeline
(refreshed 100× in last 7d / 403× in last 30d)
Each row is a source pipeline that fetched or updated this CVE on that date, with what changed. For example, "NVD update" means NVD published or revised its analysis for this CVE; "MITRE cvelistV5" means we ingested or refreshed it from the CNA feed. Most recent first.
Showing the most recent 100 of 743 total refreshes for this CVE.
- 2026-07-22 21:58 UTCVendor advisory
- 2026-07-22 21:58 UTCGHSA enrichment
- 2026-07-22 21:54 UTCEG score recompute
- 2026-07-22 19:40 UTCCISA KEV update
- 2026-07-22 17:52 UTCEG score recompute
- 2026-07-22 17:52 UTCVendor advisory
- 2026-07-22 17:52 UTCGHSA enrichment
- 2026-07-22 14:04 UTCEPSS rescore
- 2026-07-22 13:44 UTCVendor advisory
- 2026-07-22 13:44 UTCGHSA enrichment
- 2026-07-22 09:36 UTCVendor advisory
- 2026-07-22 09:36 UTCGHSA enrichment
- 2026-07-22 05:29 UTCVendor advisory
- 2026-07-22 05:29 UTCGHSA enrichment
- 2026-07-22 01:22 UTCVendor advisory
- 2026-07-22 01:22 UTCGHSA enrichment
- 2026-07-21 20:35 UTCVendor advisory
- 2026-07-21 20:35 UTCGHSA enrichment
- 2026-07-21 16:26 UTCEG score recompute
- 2026-07-21 16:26 UTCVendor advisory
- 2026-07-21 16:26 UTCGHSA enrichment
- 2026-07-21 15:21 UTCEPSS rescore
- 2026-07-21 15:21 UTCEPSS rescore
- 2026-07-21 14:37 UTCCISA KEV update
- 2026-07-21 12:19 UTCVendor advisory
Show 75 moreShow fewer
- 2026-07-21 12:19 UTCGHSA enrichment
- 2026-07-21 08:11 UTCVendor advisory
- 2026-07-21 08:11 UTCGHSA enrichment
- 2026-07-21 04:04 UTCVendor advisory
- 2026-07-21 04:03 UTCGHSA enrichment
- 2026-07-20 23:56 UTCVendor advisory
- 2026-07-20 23:56 UTCGHSA enrichment
- 2026-07-20 19:49 UTCEG score recompute
- 2026-07-20 19:49 UTCVendor advisory
- 2026-07-20 19:49 UTCGHSA enrichment
- 2026-07-20 17:03 UTCEPSS rescore
- 2026-07-20 15:42 UTCVendor advisory
- 2026-07-20 15:42 UTCGHSA enrichment
- 2026-07-20 11:36 UTCVendor advisory
- 2026-07-20 11:35 UTCGHSA enrichment
- 2026-07-20 07:28 UTCVendor advisory
- 2026-07-20 07:28 UTCGHSA enrichment
- 2026-07-20 03:21 UTCVendor advisory
- 2026-07-20 03:21 UTCGHSA enrichment
- 2026-07-19 23:13 UTCVendor advisory
- 2026-07-19 23:13 UTCGHSA enrichment
- 2026-07-19 19:07 UTCVendor advisory
- 2026-07-19 19:07 UTCGHSA enrichment
- 2026-07-19 15:00 UTCVendor advisory
- 2026-07-19 15:00 UTCGHSA enrichment
- 2026-07-19 10:53 UTCVendor advisory
- 2026-07-19 10:53 UTCGHSA enrichment
- 2026-07-19 06:46 UTCVendor advisory
- 2026-07-19 06:46 UTCGHSA enrichment
- 2026-07-19 02:39 UTCEG score recompute
- 2026-07-19 02:39 UTCVendor advisory
- 2026-07-19 02:39 UTCGHSA enrichment
- 2026-07-19 02:26 UTCEPSS rescore
- 2026-07-19 02:26 UTCEPSS rescore
- 2026-07-18 22:32 UTCVendor advisory
- 2026-07-18 22:32 UTCGHSA enrichment
- 2026-07-18 18:26 UTCVendor advisory
- 2026-07-18 18:25 UTCGHSA enrichment
- 2026-07-18 14:18 UTCVendor advisory
- 2026-07-18 14:18 UTCGHSA enrichment
- 2026-07-18 10:11 UTCEG score recompute
- 2026-07-18 10:11 UTCVendor advisory
- 2026-07-18 10:11 UTCGHSA enrichment
- 2026-07-18 10:00 UTCEPSS rescore
- 2026-07-18 06:04 UTCVendor advisory
- 2026-07-18 06:04 UTCGHSA enrichment
- 2026-07-18 01:56 UTCVendor advisory
- 2026-07-18 01:56 UTCGHSA enrichment
- 2026-07-17 21:49 UTCVendor advisory
- 2026-07-17 21:49 UTCGHSA enrichment
- 2026-07-17 17:42 UTCVendor advisory
- 2026-07-17 17:41 UTCGHSA enrichment
- 2026-07-17 13:34 UTCVendor advisory
- 2026-07-17 13:34 UTCGHSA enrichment
- 2026-07-17 09:27 UTCEG score recompute
- 2026-07-17 09:27 UTCVendor advisory
- 2026-07-17 09:27 UTCGHSA enrichment
- 2026-07-17 05:20 UTCVendor advisory
- 2026-07-17 05:20 UTCGHSA enrichment
- 2026-07-17 01:14 UTCVendor advisory
- 2026-07-17 01:13 UTCGHSA enrichment
- 2026-07-16 21:06 UTCVendor advisory
- 2026-07-16 21:06 UTCGHSA enrichment
- 2026-07-16 17:04 UTCCISA KEV update
- 2026-07-16 17:00 UTCVendor advisory
- 2026-07-16 17:00 UTCGHSA enrichment
- 2026-07-16 16:59 UTCEPSS rescore
- 2026-07-16 12:53 UTCVendor advisory
- 2026-07-16 12:53 UTCGHSA enrichment
- 2026-07-16 08:46 UTCVendor advisory
- 2026-07-16 08:46 UTCGHSA enrichment
- 2026-07-16 04:39 UTCVendor advisory
- 2026-07-16 04:39 UTCGHSA enrichment
- 2026-07-16 00:32 UTCVendor advisory
- 2026-07-16 00:32 UTCGHSA enrichment
Publicly available exploits
(9 references)Working exploit code is in the public domain (1 Metasploit module) (7 GitHub PoCs) (1 Exploit-DB entry). Defenders should treat patch urgency accordingly — public PoCs typically lead to mass-exploitation within 24-72 hours.
- GitHub PoCelongl/CVE-2014-3153First seen Oct 31, 2020
Exploiting CVE-2014-3153, AKA Towelroot.
Open source ↗ - GitHub PoCdangtunguyen/TowelRootFirst seen Sep 27, 2018
Gain root privilege by exploiting CVE-2014-3153 vulnerability
Open source ↗ - GitHub PoCzerodavinci/CVE-2014-3153-exploitFirst seen Nov 8, 2015
My exploit for kernel exploitation
Open source ↗ - GitHub PoClieanu/CVE-2014-3153First seen Jan 12, 2015
cve2014-3153 exploit for ubuntu x86
Open source ↗ - Exploit-DBEDB-35370First seen Nov 25, 2014
Linux Kernel 3.14.5 (CentOS 7 / RHEL) - 'libfutex' Local Privilege Escalation
Open source ↗ - GitHub PoCgeekben/towelrootFirst seen Sep 20, 2014
Research of CVE-2014-3153 and its famous exploit towelroot on x86
Open source ↗ - GitHub PoCandroid-rooting-tools/libfutex_exploitFirst seen Sep 13, 2014
CVE-2014-3153 exploit
Open source ↗ - GitHub PoCtimwr/CVE-2014-3153First seen Jul 24, 2014
CVE-2014-3153 aka towelroot
Open source ↗ - Metasploitexploit/android/local/futex_requeue✓ verifiedFirst seen May 3, 2014
Android 'Towelroot' Futex Requeue Kernel Exploit
Open source ↗
Frequently asked(6)
What is CVE-2014-3153?
When was CVE-2014-3153 disclosed?
Is CVE-2014-3153 actively exploited?
What is the CVSS score of CVE-2014-3153?
Which products are affected by CVE-2014-3153?
How do I remediate CVE-2014-3153?
Dependency Blast Radius
Explore the affected products and dependency analysis for CVE-2014-3153
Is Your Infrastructure Affected by CVE-2014-3153?
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.