CVE-2013-2597
Published · Updated
71Vexday Risk Score
Prioritize patching. It under exploitation confirmed by CISA and has a public proof of concept.
ssvc Actcvss 8.4epss 1.5%
from disclosure to weapon0 days
Published on NVDAug 31
1st PoCJun 11
CISA KEV+2937d
exploitation probability
1.5%top 26% of all CVEs
observed exploitation
yesCISA + VulnCheck
2 public exploit(s)
Action required by CISAfederal deadline: 2022-10-06
Apply updates per vendor instructions.
In short
A flaw in the acdb audio driver allows an attacker to overflow the system memory by sending a specially crafted command through a device file. This can give an attacker full control of the device.
Technical detail
Stack-based buffer overflow in acdb_ioctl function (audio_acdb.c) triggered by ioctl calls with oversized arguments via /dev/msm_acdb. Requires local access to the device file; leads to privilege escalation and arbitrary code execution.
Summary generated and translated by AI from the official description.
The full analysis of this CVE is available in Portuguese →
Stack-based buffer overflow in the acdb_ioctl function in audio_acdb.c in the acdb audio driver for the Linux kernel 2.6.x and 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, allows attackers to gain privileges via an application that leverages /dev/msm_acdb access and provides a large size value in an ioctl argument.
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
n/a · n/apublic PoCs found — 2
githubgithub.com/fi01/libmsm_acdb_exploit★ 12vulncheckvulncheck.com/xdb/e2481250668cunverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.