CVE-2013-6282

HIGH8.8Publicada el 20 de noviembre de 2013

The (1) get_user and (2) put_user API functions in the Linux kernel before 3.5.5 on the v6k and v7 ARM platforms do not validate certain addresses, which allows attackers to read or modify the contents of arbitrary kernel memory locations via a crafted application, as exploited in the wild against Android devices in October and November 2013.

Explotada activamente

  • En el catálogo CISA de vulnerabilidades explotadas desde el 15 sept 2022
  • Las agencias federales de EE. UU. deben corregirla antes del 6 oct 2022 (BOD 22-01)
  • Atacada 2 días antes de que la vulnerabilidad se hiciera pública

Apply updates per vendor instructions.

Fuente: CISA KEV · 15 sept 2022 16 ene 2018 20 nov 2013 19 nov 2013

Puntuación CVSS8.8 / 10CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Tipo de debilidad (CWE)CWE-20, CWE-20
Fabricanteslinux

Productos afectados

FabricantesProdottoVersioni
linuxlinux kernel< 3.2.54

Artículos relacionados

This product uses the NVD API but is not endorsed or certified by the NVD.

Base de datos CVE