Executive brief
The perf_swevent_init function in kernel/events/core.c in the Linux kernel uses an incorrect integer data type when handling the attr.config value. This leads to an out-of-bounds access of the perf_swevent_enabled array, allowing local users to escalate privileges via a crafted perf_event_open system call.
Affected products
- Linux Linux Kernel before 3.8.9
Timeline
- 2013-05-14: disclosed: Initial public disclosure and mailing list discussion.
- 2013-05-11: patched: Linux kernel version 3.8.9 released with fix.
- 2022-09-15: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.