CVE-2013-6282
Linux Kernel Improper Input Validation Vulnerability
8.8
HIGH
CVSS 3.1
⚠ KEVEPSS 67.7%
Description
The (1) get_user and (2) put_user API functions in the Linux kernel before 3.5.5 on the v6k and v7 ARM platforms do not validate certain addresses, which allows attackers to read or modify the contents of arbitrary kernel memory locations via a crafted application, as exploited in the wild against Android devices in October and November 2013.
How to fix CVE-2013-6282
To remediate CVE-2013-6282, upgrade the affected package to a fixed version below.
- —upgrade to 3.6.4-1~experimental.1 or later
Is CVE-2013-6282 being exploited?
Yes — CVE-2013-6282 is on the CISA Known Exploited Vulnerabilities (KEV) catalog. Patch immediately.
Affected packages (1)
- from 0, < 3.6.4-1~experimental.1
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH8.8 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |