CISA Known Exploited Vulnerability

CVE-2013-6282

Linux · Kernel

Linux Kernel Improper Input Validation Vulnerability

Date added
BOD 22-01 due date
CWE CWE-20
Ransomware Unknown

CISA description

The get_user and put_user API functions of the Linux kernel fail to validate the target address when being used on ARM v6k/v7 platforms. This allows an application to read and write kernel memory which could lead to privilege escalation.

Required action

Apply updates per vendor instructions.