CVE-2013-6282
linux kernel
Published 20 Nov 2013 · updated 17 Jun 2026 · Analyzed
8.8 High · CVSS 3.1, NVD
Exploited in the wild
CISA added this to its Known Exploited Vulnerabilities catalog on 15 Sept 2022, with a remediation deadline of 6 Oct 2022 for US federal agencies.
Required action: Apply updates per vendor instructions.
Description
The (1) get_user and (2) put_user API functions in the Linux kernel before 3.5.5 on the v6k and v7 ARM platforms do not validate certain addresses, which allows attackers to read or modify the contents of arbitrary kernel memory locations via a crafted application, as exploited in the wild against Android devices in October and November 2013.
References
- git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=8404663f81d212918ff85f493649a7991209fa04 · Patch
- www.codeaurora.org/projects/security-advisories/missing-access-checks-putusergetuser-kernel-api-cve-2013-6282 · Patch
- www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.5.5 · Mailing List, Vendor Advisory
- www.openwall.com/lists/oss-security/2013/11/14/11 · Mailing List
- www.securityfocus.com/bid/63734 · Third Party Advisory, VDB Entry
- www.ubuntu.com/usn/USN-2067-1 · Third Party Advisory, VDB Entry
- github.com/torvalds/linux/commit/8404663f81d212918ff85f493649a7991209fa04 · Exploit, Patch
- www.exploit-db.com/exploits/40975/ · Exploit, Third Party Advisory, VDB Entry
- www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2013-6282 · US Government Resource