Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2013-1763

31
FAUCET Score

CVE-2013-1763 is an array index error in the Linux kernel's sock_diag_rcv_msg function, affecting versions prior to 3.7.10. This vulnerability allows local users to gain privileges by sending a Netlink message with a large family value. With a CVSS score of 7.2, it is a high-severity vulnerability with local attack vector, low attack complexity, and high impact on confidentiality, integrity, and availability. While not on the KEV catalog, multiple public exploits exist on ExploitDB, indicating readily available exploit code. Despite this, there is minimal community discussion or media coverage surrounding this CVE.

Impacted Technologies

VendorProductVersion(s)CPE
>= 3.3, < 3.4.34CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 3.5, < 3.7.10CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 3.8, < 3.8.1CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 2.0

7.2HIGH

AV:L/AC:L/Au:N/C:C/I:C/A:C

Confidentiality Impact
COMPLETE
Integrity Impact
COMPLETE
Availability Impact
COMPLETE
Access Vector
LOCAL
Access Complexity
LOW
Authentication
NONE
Exploitability Score
3.9
Impact Score
10.0
CvssVersion
2.0

Exploit Intelligence

EPSS Score
4.18%
Probability of exploitation in next 30 days
EPSS Percentile
89.9%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
ExploitDB: EDB-44299 · Aug 26, 2015
This CVE's current EPSS score of 0.0418 is in the 97th percentile among its peer group of 3,241 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.5 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (2)

github_advisorypatch availablevia nvd_reference
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise MRG 2Fixed in: kernel-rt-0:3.6.11-rt30.25.el6rt
View patch

Vendor Advisories (1)

redhatCVE-2013-1763Important

kernel: sock_diag: out-of-bounds access to sock_diag_handlers[]

Feb 24, 2013

References

git.kernel.org
Broken Link
lists.opensuse.org / opensuse-security-announce/2013-03/msg00004.html
Third Party AdvisoryVDB Entry
openwall.com / lists/oss-security/2013/02/25/12
Mailing List
bugzilla.redhat.com / show_bug.cgi
Issue Tracking
github.com / torvalds/linux/commit/6e601a53566d84e1ffd25e7b6fe0b6894ffd79c0
Patch
exploit-db.com / exploits/24555
Third Party AdvisoryVDB Entry
exploit-db.com / exploits/24746
Third Party AdvisoryVDB Entry
exploit-db.com / exploits/33336
Third Party AdvisoryVDB Entry
kernel.org / pub/linux/kernel/v3.x/ChangeLog-3.7.10
Broken Link
mandriva.com / security/advisories
Broken Link
openwall.com / lists/oss-security/2013/02/24/3
Mailing List
ubuntu.com / usn/USN-1749-1
Third Party Advisory
ubuntu.com / usn/USN-1750-1
Third Party Advisory
ubuntu.com / usn/USN-1751-1
Third Party Advisory