CVE-2013-1828 describes a privilege escalation vulnerability in the Linux kernel (versions prior to 3.8.4) within the sctp_getsockopt_assoc_stats function. This flaw allows local users to gain elevated privileges by exploiting a lack of size validation before a copy_from_user operation during an SCTP_GET_ASSOC_STATS getsockopt system call. With a CVSS score of 6.9, this vulnerability is considered high severity, requiring local access and medium attack complexity, but potentially leading to complete compromise of confidentiality, integrity, and availability. While not listed on the KEV catalog and showing no active exploitation or significant community discussion, a proof-of-concept exploit (EDB-24747) is publicly available.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 3.8, < 3.8.4CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:M/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.