CVE-2013-2596

CVSS 3.1 Score 7.8 of 10 (high)

Details

Published Apr 13, 2013
Updated: Dec 20, 2024
CWE ID 190

Summary

CVE-2013-2596 is an integer overflow vulnerability affecting the fb_mmap function in the Linux kernel version prior to 3.8.9. This issue was specifically exploited in a Motorola build of Android 4.1.2, along with other products. By taking advantage of this flaw through crafted /dev/graphics/fb0 mmap2 system calls, local users could create read-write memory mappings for the entirety of kernel memory. Subsequently, they were able to gain elevated privileges.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share