Junglewise Threat Intelligence

CVE-2013-6282: Linux Kernel Improper Input Validation Vulnerability

CVE-2013-6282 · Severity: critical · CVSS 8.8 · Exploited in the wild · Published 2022-09-15

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The get_user and put_user API functions in the Linux kernel on ARM v6k and v7 platforms fail to properly validate addresses. This allows a local attacker to read or modify arbitrary kernel memory locations via a crafted application, potentially leading to privilege escalation.

Affected products

  • Linux Linux Kernel before 3.5.5

Timeline

  • 2013-10: exploited: Exploited in the wild against Android devices.
  • 2013-11-14: disclosed: Mailing list disclosure.
  • 2022-09-15: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.

Related threats