peter bassill · operator
$ cve CVE-2013-2596 JSON

CVE-2013-2596 KEV

7.8
HIGH · CVSS 3.1 · EPSS 3.2% (pctl 88)

Patch first

On CISA KEV — known exploited in the wild, due 2022-10-06.

Description

Integer overflow in the fb_mmap function in drivers/video/fbmem.c in the Linux kernel before 3.8.9, as used in a certain Motorola build of Android 4.1.2 and other products, allows local users to create a read-write memory mapping for the entirety of kernel memory, and consequently gain privileges, via crafted /dev/graphics/fb0 mmap2 system calls, as demonstrated by the Motochopper pwn program.

Scoring

CVSS7.8 (HIGH, v3.1)
VectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS3.21% — more likely to be exploited than 88% of all CVEs
WeaknessCWE-190
On CISA KEVyes — remediate by 2022-10-06
Public exploitnone known
Published2013-04-13
Last modified2026-06-16

CISA KEV

NameLinux Kernel Integer Overflow Vulnerability
Added2022-09-15
Due2022-10-06
Vendor / productLinux / Kernel
Ransomware usenone reported

Affected (6)

VendorProduct
linuxlinux kernel
motorolaandroid
motorolaatrix hd
motorolarazr hd
motorolarazr m
qualcommmsm8960

References

→ the Explorer  ·  watch your stack  ·  NVD