The (1) get_user and (2) put_user API functions in the Linux kernel before 3.5.5 on the v6k and v7 ARM platforms do not validate certain addresses, which allows attackers to read or modify the contents of arbitrary kernel memory locations via a crafted application, as exploited in the wild against Android devices in October and November 2013.
CVSS Details
- CVSS 3.1 Base Score: 8.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade linux | Jul 30, 2024 | Nov 20, 2013 |
| Huawei Euleros 2_0_sp8 | — | Upgrade kernel-headersUpgrade perfUpgrade kernel-toolsUpgrade kernelUpgrade python3-perfUpgrade kernel-tools-libsUpgrade kernel-develUpgrade kernel-sourceUpgrade bpftoolUpgrade python-perf | Mar 12, 2020 | Nov 20, 2013 |
| Ubuntu | — | Upgrade linux-image-3.2.0-1442-omap4 | Nov 8, 2024 | Nov 20, 2013 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub