Skip to content
COOEY

EXPOSURES › CVE-2013-2094

CVE-2013-2094

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2022-09-15 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2013-2094 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 72/100 exploited-in-wildunpatched

Linux Kernel CVE-2013-2094 allowed unauthorized escalation

A Linux kernel flaw enabled unauthorized users to escalate privileges, posing a high risk to DIB systems.

Shame score — Unpatched kernel vulnerability actively exploited in the wild leading to unauthorized privilege escalation.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Linux kernel fails to check all 64 bits of attr.config passed by user space, resulting to out-of-bounds access of the perf_swevent_enabled array in sw_perf_event_destroy(). Explotation allows for privilege escalation.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.