Junglewise Threat Intelligence

CVE-2013-2597: Code Aurora ACDB Audio Driver Stack-based Buffer Overflow Vulnerability

CVE-2013-2597 · Severity: critical · CVSS 8.4 · Exploited in the wild · Published 2022-09-15

Vendors: Linux Foundation.

Executive brief

A stack-based buffer overflow exists in the acdb_ioctl function in audio_acdb.c within the Code Aurora ACDB audio driver. Local attackers can gain elevated privileges by providing a large size value in an ioctl argument via /dev/msm_acdb access.

Affected products

  • Qualcomm Innovation Center (QuIC) Android contributions for MSM devices
  • Linux Foundation Linux Kernel 2.6.x, 3.x

Timeline

  • 2014-08-31: disclosed: NVD Published Date
  • 2022-09-15: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2022-09-15: exploited: Reported as exploited in the wild in advisory metadata