CVE-2013-2596
Published · Updated
Prioritize patching. It under exploitation confirmed by CISA and has a public proof of concept.
Official vendor statements in CSAF/VEX format: whether their product is affected, already fixed, or ruled out — and why. These are the vendor's assertions, not Vexday's judgment.
Apply updates per vendor instructions.
A flaw in the Linux kernel's graphics driver allows a local attacker to map and access all of kernel memory by exploiting an integer overflow, potentially gaining full system control.
An integer overflow in the fb_mmap function (drivers/video/fbmem.c) in Linux kernel versions before 3.8.9 permits local attackers to establish read-write mappings of the entire kernel memory space via crafted mmap2 syscalls on /dev/graphics/fb0, enabling privilege escalation when a graphics device is accessible.
The full analysis of this CVE is available in Portuguese →