Junglewise Threat Intelligence

CVE-2013-2094: Linux Kernel Privilege Escalation Vulnerability

CVE-2013-2094 · Severity: critical · CVSS 8.4 · Exploited in the wild · Published 2022-09-15

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The perf_swevent_init function in kernel/events/core.c in the Linux kernel uses an incorrect integer data type when handling the attr.config value. This leads to an out-of-bounds access of the perf_swevent_enabled array, allowing local users to escalate privileges via a crafted perf_event_open system call.

Affected products

  • Linux Linux Kernel before 3.8.9

Timeline

  • 2013-05-14: disclosed: Initial public disclosure and mailing list discussion.
  • 2013-05-11: patched: Linux kernel version 3.8.9 released with fix.
  • 2022-09-15: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.

Related threats