Executive brief
The get_user and put_user API functions in the Linux kernel on ARM v6k and v7 platforms fail to properly validate addresses. This allows a local attacker to read or modify arbitrary kernel memory locations via a crafted application, potentially leading to privilege escalation.
Affected products
- Linux Linux Kernel before 3.5.5
Timeline
- 2013-10: exploited: Exploited in the wild against Android devices.
- 2013-11-14: disclosed: Mailing list disclosure.
- 2022-09-15: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.