CVE-2013-6282

HIGH8.8Published on November 20, 2013

The (1) get_user and (2) put_user API functions in the Linux kernel before 3.5.5 on the v6k and v7 ARM platforms do not validate certain addresses, which allows attackers to read or modify the contents of arbitrary kernel memory locations via a crafted application, as exploited in the wild against Android devices in October and November 2013.

Actively exploited

  • In the CISA exploited-vulnerabilities catalogue since Sep 15, 2022
  • US federal agencies must remediate it by Oct 6, 2022 (BOD 22-01)
  • Attacked 2 days before the vulnerability was made public

Apply updates per vendor instructions.

Source: CISA KEV · Sep 15, 2022 Jan 16, 2018 Nov 20, 2013 Nov 19, 2013

CVSS score8.8 / 10CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weakness type (CWE)CWE-20, CWE-20
Vendorslinux

Affected products

VendorsProdottoVersioni
linuxlinux kernel< 3.2.54

Related articles

This product uses the NVD API but is not endorsed or certified by the NVD.

CVE database