CVE-2013-6282

CVSS 2.0 Score 7.2 of 10 (high)

Details

Published Nov 20, 2013
Updated: Dec 20, 2024
CWE ID 20

Summary

CVE-2013-6282 is a kernel vulnerability affecting Linux versions before 3.5.5 on v6k and v7 ARM platforms. The get_user and put_user API functions do not perform adequate address validation, enabling attackers to manipulate kernel memory locations by crafting specific applications. This issue was exploited in the wild against Android devices in October and November 2013, potentially allowing attackers to read or modify sensitive data.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share