peter bassill · operator
$ cve CVE-2013-6282 JSON

CVE-2013-6282 KEV EXPLOIT

8.8
HIGH · CVSS 3.1 · EPSS 39.7% (pctl 99)

Patch first

On CISA KEV — known exploited in the wild, due 2022-10-06.

Description

The (1) get_user and (2) put_user API functions in the Linux kernel before 3.5.5 on the v6k and v7 ARM platforms do not validate certain addresses, which allows attackers to read or modify the contents of arbitrary kernel memory locations via a crafted application, as exploited in the wild against Android devices in October and November 2013.

Scoring

CVSS8.8 (HIGH, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS39.71% — more likely to be exploited than 99% of all CVEs
WeaknessCWE-20
On CISA KEVyes — remediate by 2022-10-06
Public exploityes
Published2013-11-20
Last modified2026-06-17

CISA KEV

NameLinux Kernel Improper Input Validation Vulnerability
Added2022-09-15
Due2022-10-06
Vendor / productLinux / Kernel
Ransomware usenone reported

Affected (1)

VendorProduct
linuxlinux kernel

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD