CVE-2013-6282 KEV EXPLOIT
8.8
HIGH · CVSS 3.1 · EPSS 39.7% (pctl 99)
Patch first
On CISA KEV — known exploited in the wild, due 2022-10-06.
Description
The (1) get_user and (2) put_user API functions in the Linux kernel before 3.5.5 on the v6k and v7 ARM platforms do not validate certain addresses, which allows attackers to read or modify the contents of arbitrary kernel memory locations via a crafted application, as exploited in the wild against Android devices in October and November 2013.
Scoring
| CVSS | 8.8 (HIGH, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 39.71% — more likely to be exploited than 99% of all CVEs |
| Weakness | CWE-20 |
| On CISA KEV | yes — remediate by 2022-10-06 |
| Public exploit | yes |
| Published | 2013-11-20 |
| Last modified | 2026-06-17 |
CISA KEV
| Name | Linux Kernel Improper Input Validation Vulnerability |
|---|---|
| Added | 2022-09-15 |
| Due | 2022-10-06 |
| Vendor / product | Linux / Kernel |
| Ransomware use | none reported |
Affected (1)
| Vendor | Product |
|---|---|
| linux | linux kernel |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Google Android - get_user/put_user (Metasploit) | 2016-12-29 |
| exploit-db | Linux Kernel < 3.4.5 (Android 4.2.2/4.4 ARM) - Local Privilege Escalation | 2014-02-11 |
References
- http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=8404663f81d212918ff85f493649a7991209fa04
- http://www.codeaurora.org/projects/security-advisories/missing-access-checks-putusergetuser-kernel-api-cve-2013-6282
- http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.5.5
- http://www.openwall.com/lists/oss-security/2013/11/14/11
- http://www.securityfocus.com/bid/63734
- http://www.ubuntu.com/usn/USN-2067-1
- https://github.com/torvalds/linux/commit/8404663f81d212918ff85f493649a7991209fa04
- https://www.exploit-db.com/exploits/40975/
- http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=8404663f81d212918ff85f493649a7991209fa04
- http://www.codeaurora.org/projects/security-advisories/missing-access-checks-putusergetuser-kernel-api-cve-2013-6282
- http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.5.5
- http://www.openwall.com/lists/oss-security/2013/11/14/11
- http://www.securityfocus.com/bid/63734
- http://www.ubuntu.com/usn/USN-2067-1
- https://github.com/torvalds/linux/commit/8404663f81d212918ff85f493649a7991209fa04
- https://www.exploit-db.com/exploits/40975/
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2013-6282
→ the Explorer · watch your stack · NVD