Linux Kernel Improper Input Validation Vulnerability
cve CVE-2013-6282 3 sources, 4 claims · Watch
CISA Known Exploited Vulnerabilities writes:
Linux Kernel Improper Input Validation Vulnerability The get_user and put_user API functions of the Linux kernel fail to validate the target address when being used on ARM v6k/v7 platforms. This allows an application to read and write kernel memory which could lead to privilege escalation. Apply updates per vendor instructions. https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=8404663f81d212918ff85f493649a7991209fa04; https://nvd.nist.gov/vuln/detail/CVE-2013-6282 the claim
Linux Kernel Improper Input Validation Vulnerability The get_user and put_user API functions of the Linux kernel fail to validate the target address when being used on ARM v6k/v7 platforms. This allows an application to read and write kernel memory which could lead to privilege escalation. Apply updates per vendor instructions. https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=8404663f81d212918ff85f493649a7991209fa04; https://nvd.nist.gov/vuln/detail/CVE-2013-6282 the claim
What each source says
| Property | Source | Said | Means here |
|---|---|---|---|
| Author author | Exploit-DB | Metasploitreceipt
What the source handed over{
"aliases": "",
"application_url": "",
"author": "Metasploit",
"codes": "CVE-2013-6282",
"date_added": "2016-12-29",
"date_published": "2016-12-29",
"date_updated": "2016-12-29",
"description": "Google Android - get_user/put_user (Metasploit)",
"file": "exploits/android/local/40975.rb",
"id": "40975",
"platform": "android",
"port": "",
"screenshot_url": "",
"source_url": "https://github.com/rapid7/metasploit-framework/blob/57e4bcbf710228afe288191f4c99a553c22c34d3/modules/exploits/android/local/put_user_vroot.rb",
"tags": "Metasploit Framework (MSF)",
"type": "local",
"verified": "1"
} | — |
| Author author | Piotr Szermanreceipt
What the source handed over{
"aliases": "",
"application_url": "",
"author": "Piotr Szerman",
"codes": "CVE-2013-6282;OSVDB-99940",
"date_added": "2014-02-16",
"date_published": "2014-02-11",
"date_updated": "2016-12-01",
"description": "Linux Kernel < 3.4.5 (Android 4.2.2/4.4 ARM) - Local Privilege Escalation",
"file": "exploits/arm/local/31574.c",
"id": "31574",
"platform": "arm",
"port": "",
"screenshot_url": "",
"source_url": "",
"tags": "",
"type": "local",
"verified": "0"
} | — | |
| Cwes cwes | CISA Known Exploited Vulnerabilities | CWE-20receipt
What the source handed over{
"cveID": "CVE-2013-6282",
"cwes": "CWE-20",
"dateAdded": "2022-09-15",
"dueDate": "2022-10-06",
"forensicTriage": "No",
"knownRansomwareCampaignUse": "Unknown",
"notes": "https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=8404663f81d212918ff85f493649a7991209fa04; https://nvd.nist.gov/vuln/detail/CVE-2013-6282",
"product": "Kernel",
"requiredAction": "Apply updates per vendor instructions.",
"shortDescription": "The get_user and put_user API functions of the Linux kernel fail to validate the target address when being used on ARM v6k/v7 platforms. This allows an application to read and write kernel memory which could lead to privilege escalation.",
"vendorProject": "Linux",
"vulnerabilityName": "Linux Kernel Improper Input Validation Vulnerability"
} | — |
| Due date due_date | CISA Known Exploited Vulnerabilities | 2022-10-06receipt
What the source handed over{
"cveID": "CVE-2013-6282",
"cwes": "CWE-20",
"dateAdded": "2022-09-15",
"dueDate": "2022-10-06",
"forensicTriage": "No",
"knownRansomwareCampaignUse": "Unknown",
"notes": "https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=8404663f81d212918ff85f493649a7991209fa04; https://nvd.nist.gov/vuln/detail/CVE-2013-6282",
"product": "Kernel",
"requiredAction": "Apply updates per vendor instructions.",
"shortDescription": "The get_user and put_user API functions of the Linux kernel fail to validate the target address when being used on ARM v6k/v7 platforms. This allows an application to read and write kernel memory which could lead to privilege escalation.",
"vendorProject": "Linux",
"vulnerabilityName": "Linux Kernel Improper Input Validation Vulnerability"
} | — |
| Exploited exploited | CISA Known Exploited Vulnerabilities | yesreceipt
What the source handed over{
"cveID": "CVE-2013-6282",
"cwes": "CWE-20",
"dateAdded": "2022-09-15",
"dueDate": "2022-10-06",
"forensicTriage": "No",
"knownRansomwareCampaignUse": "Unknown",
"notes": "https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=8404663f81d212918ff85f493649a7991209fa04; https://nvd.nist.gov/vuln/detail/CVE-2013-6282",
"product": "Kernel",
"requiredAction": "Apply updates per vendor instructions.",
"shortDescription": "The get_user and put_user API functions of the Linux kernel fail to validate the target address when being used on ARM v6k/v7 platforms. This allows an application to read and write kernel memory which could lead to privilege escalation.",
"vendorProject": "Linux",
"vulnerabilityName": "Linux Kernel Improper Input Validation Vulnerability"
} | — |
| Forensic triage forensic_triage | CISA Known Exploited Vulnerabilities | falsereceipt
What the source handed over{
"cveID": "CVE-2013-6282",
"cwes": "CWE-20",
"dateAdded": "2022-09-15",
"dueDate": "2022-10-06",
"forensicTriage": "No",
"knownRansomwareCampaignUse": "Unknown",
"notes": "https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=8404663f81d212918ff85f493649a7991209fa04; https://nvd.nist.gov/vuln/detail/CVE-2013-6282",
"product": "Kernel",
"requiredAction": "Apply updates per vendor instructions.",
"shortDescription": "The get_user and put_user API functions of the Linux kernel fail to validate the target address when being used on ARM v6k/v7 platforms. This allows an application to read and write kernel memory which could lead to privilege escalation.",
"vendorProject": "Linux",
"vulnerabilityName": "Linux Kernel Improper Input Validation Vulnerability"
} | — |
| Known ransomware campaign use known_ransomware_campaign_use | CISA Known Exploited Vulnerabilities | Unknownreceipt
What the source handed over{
"cveID": "CVE-2013-6282",
"cwes": "CWE-20",
"dateAdded": "2022-09-15",
"dueDate": "2022-10-06",
"forensicTriage": "No",
"knownRansomwareCampaignUse": "Unknown",
"notes": "https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=8404663f81d212918ff85f493649a7991209fa04; https://nvd.nist.gov/vuln/detail/CVE-2013-6282",
"product": "Kernel",
"requiredAction": "Apply updates per vendor instructions.",
"shortDescription": "The get_user and put_user API functions of the Linux kernel fail to validate the target address when being used on ARM v6k/v7 platforms. This allows an application to read and write kernel memory which could lead to privilege escalation.",
"vendorProject": "Linux",
"vulnerabilityName": "Linux Kernel Improper Input Validation Vulnerability"
} | — |
| Platform platform not compared | Exploit-DB | androidreceipt
What the source handed over{
"aliases": "",
"application_url": "",
"author": "Metasploit",
"codes": "CVE-2013-6282",
"date_added": "2016-12-29",
"date_published": "2016-12-29",
"date_updated": "2016-12-29",
"description": "Google Android - get_user/put_user (Metasploit)",
"file": "exploits/android/local/40975.rb",
"id": "40975",
"platform": "android",
"port": "",
"screenshot_url": "",
"source_url": "https://github.com/rapid7/metasploit-framework/blob/57e4bcbf710228afe288191f4c99a553c22c34d3/modules/exploits/android/local/put_user_vroot.rb",
"tags": "Metasploit Framework (MSF)",
"type": "local",
"verified": "1"
} | — |
| Platform platform not compared | armreceipt
What the source handed over{
"aliases": "",
"application_url": "",
"author": "Piotr Szerman",
"codes": "CVE-2013-6282;OSVDB-99940",
"date_added": "2014-02-16",
"date_published": "2014-02-11",
"date_updated": "2016-12-01",
"description": "Linux Kernel < 3.4.5 (Android 4.2.2/4.4 ARM) - Local Privilege Escalation",
"file": "exploits/arm/local/31574.c",
"id": "31574",
"platform": "arm",
"port": "",
"screenshot_url": "",
"source_url": "",
"tags": "",
"type": "local",
"verified": "0"
} | — | |
| Platform platform not compared | Metasploit exploit modules | Android,Linuxreceipt
What the source handed over{
"actions": [],
"aliases": [],
"arch": "",
"author": [
"fi01",
"cubeundcube",
"timwr"
],
"autofilter_ports": [],
"autofilter_services": [],
"check": false,
"default_credential": false,
"description": "This module exploits a missing check in the get_user and put_user API functions\n in the linux kernel before 3.5.5. The missing checks on these functions\n allow an unprivileged user to read and write kernel memory.\n This exploit first reads the kernel memory to identify the commit_creds and\n ptmx_fops address, then uses the write primitive to execute shellcode as uid 0.\n The exploit was first discovered in the wild in the vroot rooting application.",
"disclosure_date": "2013-09-06",
"fullname": "exploit/android/local/put_user_vroot",
"is_install_path": true,
"mod_time": "2025-04-26 01:28:35 +0000",
"name": "Android get_user/put_user Exploit",
"needs_cleanup": null,
"notes": {
"Reliability": [
"unreliable-session"
],
"SideEffects": [
"artifacts-on-disk"
],
"Stability": [
"crash-safe"
]
},
"path": "/modules/exploits/android/local/put_user_vroot.rb",
"platform": "Android,Linux",
"post_auth": false,
"rank": 600,
"ref_name": "android/local/put_user_vroot",
"references": [
"CVE-2013-6282",
"URL-https://forum.xda-developers.com/t/root-share-vroot-1-6-0-3690-1-click-root-method-lenovo-a706-walkman-f800-etc.2434453/",
"URL-https://github.com/fi01/libget_user_exploit",
"URL-https://forum.xda-developers.com/t/root-saferoot-root-for-vruemj7-mk2-and-android-4-3.2565758/"
],
"rport": null,
"session_types": [
"meterpreter"
],
"targets": [
"Automatic"
],
"type": "exploit"
} | — |
| Product product | CISA Known Exploited Vulnerabilities | Kernelreceipt
What the source handed over{
"cveID": "CVE-2013-6282",
"cwes": "CWE-20",
"dateAdded": "2022-09-15",
"dueDate": "2022-10-06",
"forensicTriage": "No",
"knownRansomwareCampaignUse": "Unknown",
"notes": "https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=8404663f81d212918ff85f493649a7991209fa04; https://nvd.nist.gov/vuln/detail/CVE-2013-6282",
"product": "Kernel",
"requiredAction": "Apply updates per vendor instructions.",
"shortDescription": "The get_user and put_user API functions of the Linux kernel fail to validate the target address when being used on ARM v6k/v7 platforms. This allows an application to read and write kernel memory which could lead to privilege escalation.",
"vendorProject": "Linux",
"vulnerabilityName": "Linux Kernel Improper Input Validation Vulnerability"
} | — |
| Rank rank | Metasploit exploit modules | 600 Excellent. Cannot crash the service. A memory-corruption exploit does not qualify. receipt
What the source handed over{
"actions": [],
"aliases": [],
"arch": "",
"author": [
"fi01",
"cubeundcube",
"timwr"
],
"autofilter_ports": [],
"autofilter_services": [],
"check": false,
"default_credential": false,
"description": "This module exploits a missing check in the get_user and put_user API functions\n in the linux kernel before 3.5.5. The missing checks on these functions\n allow an unprivileged user to read and write kernel memory.\n This exploit first reads the kernel memory to identify the commit_creds and\n ptmx_fops address, then uses the write primitive to execute shellcode as uid 0.\n The exploit was first discovered in the wild in the vroot rooting application.",
"disclosure_date": "2013-09-06",
"fullname": "exploit/android/local/put_user_vroot",
"is_install_path": true,
"mod_time": "2025-04-26 01:28:35 +0000",
"name": "Android get_user/put_user Exploit",
"needs_cleanup": null,
"notes": {
"Reliability": [
"unreliable-session"
],
"SideEffects": [
"artifacts-on-disk"
],
"Stability": [
"crash-safe"
]
},
"path": "/modules/exploits/android/local/put_user_vroot.rb",
"platform": "Android,Linux",
"post_auth": false,
"rank": 600,
"ref_name": "android/local/put_user_vroot",
"references": [
"CVE-2013-6282",
"URL-https://forum.xda-developers.com/t/root-share-vroot-1-6-0-3690-1-click-root-method-lenovo-a706-walkman-f800-etc.2434453/",
"URL-https://github.com/fi01/libget_user_exploit",
"URL-https://forum.xda-developers.com/t/root-saferoot-root-for-vruemj7-mk2-and-android-4-3.2565758/"
],
"rport": null,
"session_types": [
"meterpreter"
],
"targets": [
"Automatic"
],
"type": "exploit"
} | — |
| Type type | Exploit-DB | localreceipt
What the source handed over{
"aliases": "",
"application_url": "",
"author": "Metasploit",
"codes": "CVE-2013-6282",
"date_added": "2016-12-29",
"date_published": "2016-12-29",
"date_updated": "2016-12-29",
"description": "Google Android - get_user/put_user (Metasploit)",
"file": "exploits/android/local/40975.rb",
"id": "40975",
"platform": "android",
"port": "",
"screenshot_url": "",
"source_url": "https://github.com/rapid7/metasploit-framework/blob/57e4bcbf710228afe288191f4c99a553c22c34d3/modules/exploits/android/local/put_user_vroot.rb",
"tags": "Metasploit Framework (MSF)",
"type": "local",
"verified": "1"
} | — |
| Vendor project vendor_project | CISA Known Exploited Vulnerabilities | Linuxreceipt
What the source handed over{
"cveID": "CVE-2013-6282",
"cwes": "CWE-20",
"dateAdded": "2022-09-15",
"dueDate": "2022-10-06",
"forensicTriage": "No",
"knownRansomwareCampaignUse": "Unknown",
"notes": "https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=8404663f81d212918ff85f493649a7991209fa04; https://nvd.nist.gov/vuln/detail/CVE-2013-6282",
"product": "Kernel",
"requiredAction": "Apply updates per vendor instructions.",
"shortDescription": "The get_user and put_user API functions of the Linux kernel fail to validate the target address when being used on ARM v6k/v7 platforms. This allows an application to read and write kernel memory which could lead to privilege escalation.",
"vendorProject": "Linux",
"vulnerabilityName": "Linux Kernel Improper Input Validation Vulnerability"
} | — |
| Verified verified | Exploit-DB | falsereceipt
What the source handed over{
"aliases": "",
"application_url": "",
"author": "Piotr Szerman",
"codes": "CVE-2013-6282;OSVDB-99940",
"date_added": "2014-02-16",
"date_published": "2014-02-11",
"date_updated": "2016-12-01",
"description": "Linux Kernel < 3.4.5 (Android 4.2.2/4.4 ARM) - Local Privilege Escalation",
"file": "exploits/arm/local/31574.c",
"id": "31574",
"platform": "arm",
"port": "",
"screenshot_url": "",
"source_url": "",
"tags": "",
"type": "local",
"verified": "0"
} | — |
| Verified verified | truereceipt
What the source handed over{
"aliases": "",
"application_url": "",
"author": "Metasploit",
"codes": "CVE-2013-6282",
"date_added": "2016-12-29",
"date_published": "2016-12-29",
"date_updated": "2016-12-29",
"description": "Google Android - get_user/put_user (Metasploit)",
"file": "exploits/android/local/40975.rb",
"id": "40975",
"platform": "android",
"port": "",
"screenshot_url": "",
"source_url": "https://github.com/rapid7/metasploit-framework/blob/57e4bcbf710228afe288191f4c99a553c22c34d3/modules/exploits/android/local/put_user_vroot.rb",
"tags": "Metasploit Framework (MSF)",
"type": "local",
"verified": "1"
} | — |
vulnerability
| Linux Kernel Improper Input Validation Vulnerability zetlyn/cve-kev · 2022-09-15 | cwes CWE-20 due_date 2022-10-06 exploited yes forensic_triage false known_ransomware_campaign_use Unknown product Kernel vendor_project Linux |
exploit
| Android get_user/put_user Exploit zetlyn/cve-metasploit · 2013-09-06 | platform Android,Linux rank 600 | source |
| Google Android - get_user/put_user (Metasploit) zetlyn/cve-exploitdb · 2016-12-29 | author Metasploit platform android type local verified true | source |
| Linux Kernel < 3.4.5 (Android 4.2.2/4.4 ARM) - Local Privilege Escalation zetlyn/cve-exploitdb · 2014-02-11 | author Piotr Szerman platform arm type local verified false | source |