peter bassill · operator
$ cve CVE-2013-2094 JSON

CVE-2013-2094 KEV EXPLOIT

8.4
HIGH · CVSS 3.1 · EPSS 47.7% (pctl 99)

Patch first

On CISA KEV — known exploited in the wild, due 2022-10-06.

Description

The perf_swevent_init function in kernel/events/core.c in the Linux kernel before 3.8.9 uses an incorrect integer data type, which allows local users to gain privileges via a crafted perf_event_open system call.

Scoring

CVSS8.4 (HIGH, v3.1)
VectorCVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS47.71% — more likely to be exploited than 99% of all CVEs
WeaknessCWE-189
On CISA KEVyes — remediate by 2022-10-06
Public exploityes
Published2013-05-14
Last modified2026-06-16

CISA KEV

NameLinux Kernel Privilege Escalation Vulnerability
Added2022-09-15
Due2022-10-06
Vendor / productLinux / Kernel
Ransomware usenone reported

Affected (1)

VendorProduct
linuxlinux kernel

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD