CVE-2013-2596highunder attackCWE-190

CVE-2013-2596

Published · Updated

71Vexday Risk Score

Prioritize patching. It under exploitation confirmed by CISA and has a public proof of concept.

ssvc Actcvss 7.8epss 3.2%
from disclosure to weapon94 days
Published on NVDApr 13
1st PoC+94d
CISA KEV+3442d
exploitation probability
3.2%top 12% of all CVEs
observed exploitation
yesCISA + VulnCheck
2 public exploit(s)
What the vendors declare (VEX)

Official vendor statements in CSAF/VEX format: whether their product is affected, already fixed, or ruled out — and why. These are the vendor's assertions, not Vexday's judgment.

Fixed
18 products (854 components)
Red Hat Enterprise Linux (v. 5 server) · Red Hat Enterprise Linux Desktop (v. 5 client) · Red Hat Enterprise Linux Compute Node Optional EUS (v. 6.5) · Red Hat Enterprise Linux Desktop (v. 6) · Red Hat Enterprise Linux Desktop Optional (v. 6) · and others 13
Not affected
2 products (29 components) — because the vulnerable code is not present in the product
Red Hat Enterprise Linux 7 · Red Hat Enterprise MRG 2
Action required by CISAfederal deadline: 2022-10-06

Apply updates per vendor instructions.

In short

A flaw in the Linux kernel's graphics driver allows a local attacker to map and access all of kernel memory by exploiting an integer overflow, potentially gaining full system control.

Technical detail

An integer overflow in the fb_mmap function (drivers/video/fbmem.c) in Linux kernel versions before 3.8.9 permits local attackers to establish read-write mappings of the entire kernel memory space via crafted mmap2 syscalls on /dev/graphics/fb0, enabling privilege escalation when a graphics device is accessible.

Summary generated and translated by AI from the official description.

The full analysis of this CVE is available in Portuguese →

Integer overflow in the fb_mmap function in drivers/video/fbmem.c in the Linux kernel before 3.8.9, as used in a certain Motorola build of Android 4.1.2 and other products, allows local users to create a read-write memory mapping for the entirety of kernel memory, and consequently gain privileges, via crafted /dev/graphics/fb0 mmap2 system calls, as demonstrated by the Motochopper pwn program.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected products
n/a · n/a
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.