CVE-2013-2094 is a local privilege escalation vulnerability affecting the Linux kernel before version 3.8.9, specifically within the perf_swevent_init function. This flaw, due to an incorrect integer data type, allows local users to gain elevated privileges through a crafted perf_event_open system call. Rated with a high CVSS score of 8.4, this vulnerability is easily exploitable locally with low attack complexity, leading to complete compromise of confidentiality, integrity, and availability. Its high EPSS score and perfect FAUCET Risk Score further underscore its critical severity. This CVE is actively exploited in the wild, as confirmed by its inclusion in the KEV catalog, and multiple public exploits are available on ExploitDB. It has garnered significant community attention, with numerous discussions and media coverage, highlighting its historical impact and continued relevance.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 3.0.75CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 3.1, < 3.2.45CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 3.3, < 3.4.42CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 3.5, < 3.8.9CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:L/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.5 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Proxmox VE Kernel 2.6.32-23-pve fixes CVE-2013-2094
Nov 19, 2013Kernel update fixes CVE-2013-2094
Oct 1, 2013Kernel update fixes CVE-2013-2094
Oct 1, 2013Linux kernel vulnerability (CVE-2013-2094)
May 15, 2013kernel: perf_swevent_enabled array out-of-bound access
May 14, 2013The perf_swevent_init function in kernel/events/core.c in the Linux kernel before 3.8.9 uses an incorrect integer data type which allows local users to gain privileges via a crafted perf_event_open system call.
May 2, 2013pve-kernel-2.6.32 update fixes CVE-2013-2094
Proxmox VE Kernel Update to Fix CVE-2013-2094
Kernel update fixes CVE-2013-2094
Kernel vulnerability fix (CVE-2013-2094)
Proxmox VE Kernel Update fixes CVE-2013-2094