Executive brief
An integer overflow vulnerability in the fb_mmap function in drivers/video/fbmem.c in the Linux kernel allows local users to create read-write memory mappings for the entirety of kernel memory. This flaw can be exploited via crafted /dev/graphics/fb0 mmap2 system calls to gain elevated privileges.
Affected products
- Linux Linux Kernel before 3.8.9
- Motorola Android 4.1.2
Timeline
- 2013-04-16: disclosed: Mailing list disclosure of the vulnerability.
- 2013-05-04: patched: Linux kernel 3.8.9 released with fix.
- 2022-09-15: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.
- 2022-09-15: advisory: NVD publication date.