CVE-2013-2094

linux kernel

Published 14 May 2013 · updated 16 Jun 2026 · Analyzed

8.4 High · CVSS 3.1, CISA ADP

Exploited in the wild

CISA added this to its Known Exploited Vulnerabilities catalog on 15 Sept 2022, with a remediation deadline of 6 Oct 2022 for US federal agencies.

Required action: Apply updates per vendor instructions.

Description

The perf_swevent_init function in kernel/events/core.c in the Linux kernel before 3.8.9 uses an incorrect integer data type, which allows local users to gain privileges via a crafted perf_event_open system call.

References