Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2013-6282

91
FAUCET Score

CVE-2013-6282 is a critical vulnerability in the Linux kernel before version 3.5.5, specifically affecting v6k and v7 ARM platforms, including Android devices. It stems from a lack of address validation in the get_user and put_user API functions, allowing attackers to read or modify arbitrary kernel memory. This flaw carries a CVSS score of 8.8 (HIGH) due to its network-accessible, low-complexity nature, enabling high impact on confidentiality, integrity, and availability. The vulnerability is actively exploited in the wild, as evidenced by its inclusion in CISA's KEV catalog and the availability of Metasploit modules and ExploitDB entries. It has garnered significant community attention and media coverage, indicating its widespread impact and the urgency of patching.

Impacted Technologies

VendorProductVersion(s)CPE
< 3.2.54CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 3.3, < 3.4.12CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 3.5, < 3.5.5CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

8.8HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
2.8
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
39.71%
Probability of exploitation in next 30 days
EPSS Percentile
98.5%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
Added to KEV · Sep 15, 2022
Metasploit: Android get_user/put_user Exploit · Sep 6, 2013
ExploitDB: EDB-40975 · Dec 29, 2016
This CVE's current EPSS score of 0.3971 is in the 98th percentile among its peer group of 17,844 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (1)

github_advisorypatch availablevia nvd_reference
View patch

Vendor Advisories (1)

redhatCVE-2013-6282

CVE-2013-6282

References

cisa.gov / known-exploited-vulnerabilities-catalog
US Government Resource
git.kernel.org
Patch
github.com / torvalds/linux/commit/8404663f81d212918ff85f493649a7991209fa04
ExploitPatch
exploit-db.com / exploits/40975
ExploitThird Party AdvisoryVDB Entry
codeaurora.org / projects/security-advisories/missing-access-checks-putusergetuser-kernel-api-cve-2013-6282
Patch
kernel.org / pub/linux/kernel/v3.x/ChangeLog-3.5.5
Mailing ListVendor Advisory
openwall.com / lists/oss-security/2013/11/14/11
Mailing List
securityfocus.com / bid/63734
Third Party AdvisoryVDB Entry
ubuntu.com / usn/USN-2067-1
Third Party AdvisoryVDB Entry