CVE-2013-6282
Linux Kernel Improper Input Validation Vulnerability
Does this matter?
Known to be exploited in the wild (CISA KEV, CISA remediation deadline 6 October 2022). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.
Description
The (1) get_user and (2) put_user API functions in the Linux kernel before 3.5.5 on the v6k and v7 ARM platforms do not validate certain addresses, which allows attackers to read or modify the contents of arbitrary kernel memory locations via a crafted application, as exploited in the wild against Android devices in October and November 2013.
- CVSS 3.1
- 8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 39.71% probability · 99th percentile
- CISA KEV
- Listed 15 September 2022 · due 6 October 2022
- Weakness
- CWE-20
- Affected
- linux/linux kernel
- Source
- cve@mitre.org
CISA notes
Apply updates per vendor instructions. https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=8404663f81d212918ff85f493649a7991209fa04; https://nvd.nist.gov/vuln/detail/CVE-2013-6282
References
- http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=8404663f81d212918ff85f493649a7991209fa04Patch
- http://www.codeaurora.org/projects/security-advisories/missing-access-checks-putusergetuser-kernel-api-cve-2013-6282Patch
- http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.5.5Mailing List, Vendor Advisory
- http://www.openwall.com/lists/oss-security/2013/11/14/11Mailing List
- http://www.securityfocus.com/bid/63734Third Party Advisory, VDB Entry
- http://www.ubuntu.com/usn/USN-2067-1Third Party Advisory, VDB Entry
- https://github.com/torvalds/linux/commit/8404663f81d212918ff85f493649a7991209fa04Exploit, Patch
- https://www.exploit-db.com/exploits/40975/Exploit, Third Party Advisory, VDB Entry
- http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=8404663f81d212918ff85f493649a7991209fa04Patch
- http://www.codeaurora.org/projects/security-advisories/missing-access-checks-putusergetuser-kernel-api-cve-2013-6282Patch
- http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.5.5Mailing List, Vendor Advisory
- http://www.openwall.com/lists/oss-security/2013/11/14/11Mailing List
- http://www.securityfocus.com/bid/63734Third Party Advisory, VDB Entry
- http://www.ubuntu.com/usn/USN-2067-1Third Party Advisory, VDB Entry
- https://github.com/torvalds/linux/commit/8404663f81d212918ff85f493649a7991209fa04Exploit, Patch
- https://www.exploit-db.com/exploits/40975/Exploit, Third Party Advisory, VDB Entry
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2013-6282US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.