CVE-2013-6282
The (1) get_user and (2) put_user API functions in the Linux kernel before 3.5.5 on the v6k and v7 ARM platforms do not validate certain addresses, which allows attackers to read or modify the contents of arbitrary kernel memory locations via a crafted application, as exploited in the wild against Android devices in October and November 2013.
- Affected products
- Linux Kernel
- Linux Linux Kernel
- < 3.2.54, 3.4.12, 3.5.5
- Fix
- Available
- CVSS 3.1
- 8.8 HIGH
- EPSS
- 39.7% (99th percentile)
- Weakness
- CWE-20
- NVD status
- Analyzed
- Published
- 2013-11-19
CVE-2013-6282 at NVD
9 known exploits for CVE-2013-6282
Proof-of-concept code and exploit modules indexed by Sploitus
libget_user_exploit
Google Android - get_user/put_user (Metasploit)
Android get_user/put_user Exploit
Android get_user/put_user Exploit
Exploit for Improper Input Validation in Linux Linux_Kernel
Linux ARM - Local Root Exploit
Linux Kernel 3.4.5 (Android 4.2.24.4 ARM) - Local Privilege Escalation
Linux Kernel < 3.4.5 (Android 4.2.2/4.4 ARM) - Local Privilege Escalation
Android get_user/put_user Exploit