CVE-2014-3153 is a local privilege-escalation vulnerability in the Linux kernel futex subsystem, affecting kernels through 3.14.5. The futex_requeue handling of Priority Inheritance (PI) futexes fails to ensure that the source and destination futex addresses differ. A crafted FUTEX_REQUEUE operation using identical addresses can leave a PI futex waiter linked in the waiter list after its associated state has been invalidated or returned from the relevant path. Subsequent kernel-stack reuse can then corrupt waiter-list state and enable unsafe kernel-memory modification. The vulnerable path is associated with PI futex requeue handling, including futex_wait_requeue_pi().
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
7 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This repository contains a single Metasploit module (modules/exploits/android/local/futex_requeue.rb) that exploits the 'futex_requeue' vulnerability (CVE-2014-3153), also known as the 'Towelroot' exploit, in the Linux kernel on Android devices. The exploit targets devices with kernels built before June 2014 (Android < 4.5.0), including various Samsung and Nexus models. The module works by loading a malicious shared object (CVE-2014-3153.so) onto the device, which is then used to escalate privileges and execute a Meterpreter payload, typically providing a reverse shell to the attacker. The exploit is operational and requires a Meterpreter session on the device. The code is written in Ruby and is designed to be used within the Metasploit framework. The main attack vector is local privilege escalation, and the module automatically selects the appropriate target configuration based on device properties. No network endpoints are hardcoded, but the payload can be configured to use reverse TCP connections.
This repository contains a local privilege escalation exploit targeting Android devices, likely vulnerable to the futex requeue bug (CVE-2014-3153 or similar). The main exploit logic is implemented in 'futex_requeue.c', with 'main.c' serving as the entry point. The exploit is designed to be built using the Android NDK (as indicated by 'Android.mk' and 'Makefile'), targeting the armeabi architecture. The exploit works by manipulating futexes and kernel structures to achieve code execution as root. Upon successful exploitation, it spawns an interactive root shell by executing '/system/bin/sh -i'. The Makefile provides commands to build, push, and run the exploit on a connected Android device via adb. Key fingerprintable endpoints include the use of '/system/bin/sh', '/dev/ptmx', and the deployment path '/data/local/tmp/futex'. The code is operational and provides a working root shell payload, but is not part of a larger exploitation framework.
This repository contains a local privilege escalation exploit for the Linux kernel vulnerability CVE-2014-3153 (Towelroot), specifically targeting Ubuntu 12.04.2 and 14.04 x86 systems running kernel versions up to 3.14. The exploit is implemented in C (mytowel.c) and leverages a race condition in the futex subsystem to manipulate kernel memory and escalate privileges to root. The code sets up a local TCP socket on 127.0.0.1:5551 for internal communication and interacts with the /dev/ptmx device as part of the exploitation process. The README provides compilation and usage instructions. The exploit is operational and, if successful, provides root access on the vulnerable system. No remote attack vector is present; the exploit must be run locally on the target machine.
This repository contains a local privilege escalation exploit targeting the Linux kernel futex subsystem, which is also present in Android devices. The main files are 'exploit.c' (the core exploit logic), 'futex.c' (helper routines for kernel memory manipulation and a local server for memory requests), and 'futex.h' (header for futex-related functions). The exploit works by creating a race condition in the futex syscall handling, allowing arbitrary kernel memory read/write and ultimately escalating privileges to root. The exploit sets up a local server on 127.0.0.1:5553 to process kernel memory requests and interacts with kernel structures via futex manipulation. The Makefile (Android.mk) is provided for building the exploit as a static library, likely for use on Android devices. The exploit is operational and provides a working local privilege escalation payload, but is not part of a larger framework.
This repository contains a local privilege escalation exploit targeting the Linux kernel futex subsystem (CVE not explicitly mentioned, but matches the Towelroot vulnerability, CVE-2014-3153). The exploit leverages a flaw in the futex_requeue function, allowing a local user to manipulate kernel data structures and escalate privileges to root. The main exploit logic is implemented in 'privilege_escalation.c', which orchestrates the attack by creating and manipulating futexes, forging kernel waiter structures, leaking kernel addresses, and ultimately overwriting credential structures to gain root privileges. The exploit then spawns a root shell using '/bin/sh'. Supporting files include 'futex.c' and 'futex.h' (implementing futex-related syscalls and data structures), 'kernel_crash.c' (demonstrates kernel crash via futex abuse), and 'notes.md' (provides detailed technical background and attack flow). The Makefile builds the two main binaries. The attack vector is local, requiring code execution on the target system. The only fingerprintable endpoint is the use of '/bin/sh' to spawn a shell. The exploit is operational, with a hardcoded payload and detailed technical implementation.
This repository contains the source code for the TowelRoot exploit, which targets the futex vulnerability in the Linux kernel (CVE-2014-3153) to gain root privileges on Android devices. The main file, TowelRoot.c, is a C program that implements the exploit logic. It uses advanced techniques such as manipulating kernel memory structures, exploiting race conditions in the futex syscall, and interacting with pseudo-terminal devices (/dev/ptmx, /dev/pts/*) to achieve privilege escalation. The exploit sets up a local TCP socket on 127.0.0.1:1337, which may be used for communication or to provide a root shell. The code is operational and requires compilation and execution on a vulnerable Android device. The README provides a brief overview and references the targeted CVE. The repository is focused and contains only the exploit code and documentation.
This repository contains a research implementation of the famous 'towelroot' exploit targeting CVE-2014-3153, a privilege escalation vulnerability in the Linux kernel's futex subsystem. The main file, 'towelroot.c', is a C program that exploits this vulnerability on IA (x86) architecture. The exploit works by manipulating kernel memory structures to escalate privileges to root. It optionally executes a user-supplied command as root if provided as an argument. The code sets up a local TCP socket on 127.0.0.1:5551 for internal communication and interacts with the '/dev/ptmx' device as part of the exploitation process. The repository is structured simply, with a README, a .gitignore, and the main exploit source code. The exploit is operational and demonstrates a working local privilege escalation attack, but is not weaponized for mass deployment.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An Android/Linux kernel privilege escalation vulnerability (commonly referred to as the 'Kernel Waiter' exploit) that was leveraged post-leak, including for mobile ransomware propagation.
A serious Linux kernel futex vulnerability involving improper handling of a priority-inheritance futex waiter left linked on the kernel stack, enabling kernel memory corruption and privilege escalation. It became widely known through the Towelroot exploit.
A Linux kernel privilege escalation vulnerability used by the Towelroot rooting tool to gain root access on affected Android devices with unpatched kernels.
An important local privilege-escalation vulnerability in the Linux kernel futex subsystem involving requeuing of certain Priority Inheritance (PI) futexes.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.