CVE-2013-2597 is a stack-based buffer overflow vulnerability in the acdb_ioctl function of the Linux kernel's audio_acdb driver, affecting Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products. An attacker can exploit this by providing a large size value in an ioctl argument through an application leveraging /dev/msm_acdb access. This vulnerability carries a high CVSS score of 8.4, indicating high impact on confidentiality, integrity, and availability, with a local attack vector and low attack complexity. Notably, this CVE is listed in CISA's KEV catalog, confirming active exploitation, despite no public exploit code being readily available in Metasploit, Nuclei, or ExploitDB. It has garnered significant community discussion and media coverage, indicating widespread awareness and concern.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.6.29CPE matchmatch criteria | cpe:2.3:o:codeaurora:android-msm:2.6.29:*:*:*:*:*:*:* | ||
3.2.54CPE matchmatch criteria | cpe:2.3:o:codeaurora:android-msm:3.2.54:*:*:*:*:*:*:* | ||
3.2.55CPE matchmatch criteria | cpe:2.3:o:codeaurora:android-msm:3.2.55:*:*:*:*:*:*:* | ||
3.2.56CPE matchmatch criteria | cpe:2.3:o:codeaurora:android-msm:3.2.56:*:*:*:*:*:*:* | ||
3.2.57CPE matchmatch criteria | cpe:2.3:o:codeaurora:android-msm:3.2.57:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:L/Au:N/C:C/I:C/A:C
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.5 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.