CVE-2013-1858 describes a privilege escalation vulnerability in the Linux kernel before version 3.8.3, specifically within the clone system-call implementation when using CLONE_NEWUSER and CLONE_FS flags. This flaw allows local users to gain elevated privileges by manipulating chroot and exploiting shared directory structures between parent and child processes. With a CVSS score of 7.2, this vulnerability is considered high severity due to its local attack vector, low attack complexity, and complete compromise of confidentiality, integrity, and availability. While no known public exploits (Metasploit, Nuclei, ExploitDB) are available and it is not on CISA's KEV catalog, its EPSS score indicates a low but non-zero probability of exploitation, and there is no significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 3.8.2CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
3.0CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:3.0:rc1:*:*:*:*:*:* | ||
3.0CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:3.0:rc2:*:*:*:*:*:* | ||
3.0CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:3.0:rc3:*:*:*:*:*:* | ||
3.0CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:3.0:rc4:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:L/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.5 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.