CVE-2013-6282

HIGH8.8Pubblicata il 20 novembre 2013

The (1) get_user and (2) put_user API functions in the Linux kernel before 3.5.5 on the v6k and v7 ARM platforms do not validate certain addresses, which allows attackers to read or modify the contents of arbitrary kernel memory locations via a crafted application, as exploited in the wild against Android devices in October and November 2013.

Sfruttata attivamente

  • Nel catalogo CISA delle vulnerabilità sfruttate dal 15 set 2022
  • Le agenzie federali statunitensi devono correggerla entro il 6 ott 2022 (direttiva BOD 22-01)
  • Attaccata 2 giorni prima che la vulnerabilità fosse resa pubblica

Apply updates per vendor instructions.

Fonte: CISA KEV · 15 set 2022 16 gen 2018 20 nov 2013 19 nov 2013

Punteggio CVSS8.8 / 10CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Tipo di debolezza (CWE)CWE-20, CWE-20
Vendorlinux

Prodotti coinvolti

VendorProdottoVersioni
linuxlinux kernel< 3.2.54

Articoli correlati

This product uses the NVD API but is not endorsed or certified by the NVD.

Database CVE