← Back to browse · API

CVE-2013-6282

Severity
HIGH
CVSS
8.8
EPSS
0.39711
Risk score
74.1
CISA KEV
Yes
PoC
No
Published
2022-09-15
Modified
2022-09-15
First seen
2026-08-07
Aliases
EUVD-2013-6110, GHSA-7P8V-5R94-XC7R
Products
Linux:Kernel, n/a:n/a n/a
Sources
euvd EUVD-2013-6110
cisa.gov CVE-2013-6282

Description

The get_user and put_user API functions of the Linux kernel fail to validate the target address when being used on ARM v6k/v7 platforms. This allows an application to read and write kernel memory which could lead to privilege escalation.

References