CVE-2013-6282 is a critical vulnerability in the Linux kernel before version 3.5.5, specifically affecting v6k and v7 ARM platforms, including Android devices. It stems from a lack of address validation in the get_user and put_user API functions, allowing attackers to read or modify arbitrary kernel memory. This flaw carries a CVSS score of 8.8 (HIGH) due to its network-accessible, low-complexity nature, enabling high impact on confidentiality, integrity, and availability. The vulnerability is actively exploited in the wild, as evidenced by its inclusion in CISA's KEV catalog and the availability of Metasploit modules and ExploitDB entries. It has garnered significant community attention and media coverage, indicating its widespread impact and the urgency of patching.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 3.2.54CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 3.3, < 3.4.12CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 3.5, < 3.5.5CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.