Vulnerability Description
The (1) get_user and (2) put_user API functions in the Linux kernel before 3.5.5 on the v6k and v7 ARM platforms do not validate certain addresses, which allows attackers to read or modify the contents of arbitrary kernel memory locations via a crafted application, as exploited in the wild against Android devices in October and November 2013.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux Kernel | < 3.2.54 |
Related Weaknesses (CWE)
References
- http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=Patch
- http://www.codeaurora.org/projects/security-advisories/missing-access-checks-putPatch
- http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.5.5Mailing ListVendor Advisory
- http://www.openwall.com/lists/oss-security/2013/11/14/11Mailing List
- http://www.securityfocus.com/bid/63734Third Party AdvisoryVDB Entry
- http://www.ubuntu.com/usn/USN-2067-1Third Party AdvisoryVDB Entry
- https://github.com/torvalds/linux/commit/8404663f81d212918ff85f493649a7991209fa0ExploitPatch
- https://www.exploit-db.com/exploits/40975/ExploitThird Party AdvisoryVDB Entry
- http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=Patch
- http://www.codeaurora.org/projects/security-advisories/missing-access-checks-putPatch
- http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.5.5Mailing ListVendor Advisory
- http://www.openwall.com/lists/oss-security/2013/11/14/11Mailing List
- http://www.securityfocus.com/bid/63734Third Party AdvisoryVDB Entry
- http://www.ubuntu.com/usn/USN-2067-1Third Party AdvisoryVDB Entry
- https://github.com/torvalds/linux/commit/8404663f81d212918ff85f493649a7991209fa0ExploitPatch
FAQ
What is CVE-2013-6282?
CVE-2013-6282 is a vulnerability with a CVSS score of 8.8 (HIGH). The (1) get_user and (2) put_user API functions in the Linux kernel before 3.5.5 on the v6k and v7 ARM platforms do not validate certain addresses, which allows attackers to read or modify the content...
How severe is CVE-2013-6282?
CVE-2013-6282 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2013-6282?
Check the references section above for vendor advisories and patch information. Affected products include: Linux Linux Kernel.