SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAnalyzed

CVE-2013-6282

Linux Kernel Improper Input Validation Vulnerability

KEVHIGH 8.8EPSS 39.7%

Does this matter?

Known to be exploited in the wild (CISA KEV, CISA remediation deadline 6 October 2022). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.

Description

The (1) get_user and (2) put_user API functions in the Linux kernel before 3.5.5 on the v6k and v7 ARM platforms do not validate certain addresses, which allows attackers to read or modify the contents of arbitrary kernel memory locations via a crafted application, as exploited in the wild against Android devices in October and November 2013.

CVSS 3.1
8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS
39.71% probability · 99th percentile
CISA KEV
Listed 15 September 2022 · due 6 October 2022
Weakness
CWE-20
Affected
linux/linux kernel
Source
cve@mitre.org

CISA notes

Apply updates per vendor instructions. https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=8404663f81d212918ff85f493649a7991209fa04; https://nvd.nist.gov/vuln/detail/CVE-2013-6282

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.