CVE-2013-2595 describes a privilege escalation vulnerability in the MSM camera driver within the Linux kernel (versions 2.6.x and 3.x), specifically impacting Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products. This flaw allows attackers to gain elevated privileges through a crafted application by exploiting an unrestricted mmap interface via MSM_CAM_IOCTL_SET_MEM_MAP_INFO ioctl calls. With a CVSS score of 7.2, it is a high-severity vulnerability, indicating local access with low attack complexity and complete confidentiality, integrity, and availability impacts. While there is no evidence of active exploitation (KEV: No) and no public exploit code (Metasploit, Nuclei, ExploitDB: None), the vulnerability has garnered significant community discussion and media coverage, suggesting awareness within the security community.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.6.29CPE matchmatch criteria | cpe:2.3:o:codeaurora:android-msm:2.6.29:*:*:*:*:*:*:* | ||
3.2.54CPE matchmatch criteria | cpe:2.3:o:codeaurora:android-msm:3.2.54:*:*:*:*:*:*:* | ||
3.2.55CPE matchmatch criteria | cpe:2.3:o:codeaurora:android-msm:3.2.55:*:*:*:*:*:*:* | ||
3.2.56CPE matchmatch criteria | cpe:2.3:o:codeaurora:android-msm:3.2.56:*:*:*:*:*:*:* | ||
3.2.57CPE matchmatch criteria | cpe:2.3:o:codeaurora:android-msm:3.2.57:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:L/Au:N/C:C/I:C/A:C
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.5 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.