CVE-2013-2596
גבוהה 7.8 מנוצלת בשטח (KEV)
ניצול פעיל מאומת — קטלוג CISA KEV
- שם
- Linux Kernel Integer Overflow Vulnerability
- נוסף לקטלוג
- יעד טיפול (פדרלי)
- פעולה נדרשת
- Apply updates per vendor instructions.
תיאור (מקור, אנגלית)
Integer overflow in the fb_mmap function in drivers/video/fbmem.c in the Linux kernel before 3.8.9, as used in a certain Motorola build of Android 4.1.2 and other products, allows local users to create a read-write memory mapping for the entirety of kernel memory, and consequently gain privileges, via crafted /dev/graphics/fb0 mmap2 system calls, as demonstrated by the Motochopper pwn program.
מדדים
- CVSS 3.1
-
7.8 (HIGH)
מקור הציון: NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H - EPSS — סבירות ניצול
- 3% (אחוזון 100) נכון ל-24/7/2026
- CWE
- CWE-190
מוצרים מושפעים
linux: linux kernel; motorola: android; motorola: atrix hd; motorola: razr hd; motorola: razr m; qualcomm: msm8960
קישורים
- http://marc.info/?l=linux-kernel&m=136616837923938&w=2 Mailing ListPatchThird Party Advisory
- http://www.oracle.com/technetwork/topics/security/linuxbulletinjan2016-2867209… PatchThird Party Advisory
- https://github.com/torvalds/linux/commit/b4cbb197c7e7a68dbad0d491242e3ca67420c… Patch
- https://github.com/torvalds/linux/commit/fc9bbca8f650e5f738af8806317c0a041a48a… ExploitPatch
- http://marc.info/?l=linux-kernel&m=136616837923938&w=2 Mailing ListPatchThird Party Advisory
- http://www.oracle.com/technetwork/topics/security/linuxbulletinjan2016-2867209… PatchThird Party Advisory
- https://github.com/torvalds/linux/commit/b4cbb197c7e7a68dbad0d491242e3ca67420c… Patch
- https://github.com/torvalds/linux/commit/fc9bbca8f650e5f738af8806317c0a041a48a… ExploitPatch
- http://forum.xda-developers.com/showthread.php?t=2255491 Exploit
- http://www.droid-life.com/2013/04/09/root-method-released-for-droid-razr-hd-ru… ExploitIssue TrackingThird Party Advisory