KEVIntel
8.8
CVSS
High

CVE-2013-6282

PUBLISHED

The (1) get_user and (2) put_user API functions in the Linux kernel before 3.5.5 on the v6k and v7 ARM platforms do not validate certain addresses,...

Exploited in the wild Remote Low complexity No user interaction
Vendor
Linux
Product
Linux Kernel
Published
Nov 19, 2013
EPSS

Description

The (1) get_user and (2) put_user API functions in the Linux kernel before 3.5.5 on the v6k and v7 ARM platforms do not validate certain addresses, which allows attackers to read or modify the contents of arbitrary kernel memory locations via a crafted application, as exploited in the wild against Android devices in October and November 2013.

linux android cisa metasploit

CVSS scores

CVSS v3.1 8.8 High

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CVSS v2.0 7.2

AV:L/AC:L/Au:N/C:C/I:C/A:C

Exploitation status

Exploited in the wild

Recorded 2022-09-15 00:00:00 UTC · Source

SSVC decision points

Exploitation
active
Automatable
No
Technical impact
total

Known exploited vulnerability sources

Catalogues that list this CVE as a known exploited vulnerability.

Source Added
CISA Sep 15, 2022

Scanner integrations

Potential proof of concepts

These PoCs are unverified and could contain malware. Use at your own risk.

put_user_vroot

metasploit · Created Unknown

Metasploit module for CVE-2013-6282

timwr/CVE-2013-6282

github · Created 2016-12-19 16:14:18 UTC · 20 stars

CVE-2013-6282 proof of concept for Android

Timeline

  • CVE ID Reserved

  • CVE Published to Public

  • Added to KEVIntel

  • Detected by Metasploit