Junglewise Threat Intelligence

CVE-2013-2596: Linux Kernel Integer Overflow Vulnerability

CVE-2013-2596 · Severity: critical · CVSS 7.8 · Exploited in the wild · Published 2022-09-15

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

An integer overflow vulnerability in the fb_mmap function in drivers/video/fbmem.c in the Linux kernel allows local users to create read-write memory mappings for the entirety of kernel memory. This flaw can be exploited via crafted /dev/graphics/fb0 mmap2 system calls to gain elevated privileges.

Affected products

  • Linux Linux Kernel before 3.8.9
  • Motorola Android 4.1.2

Timeline

  • 2013-04-16: disclosed: Mailing list disclosure of the vulnerability.
  • 2013-05-04: patched: Linux kernel 3.8.9 released with fix.
  • 2022-09-15: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.
  • 2022-09-15: advisory: NVD publication date.

Related threats