Vulnerability Database

289,599

Total vulnerabilities in the database

CVE-2013-2596

Integer overflow in the fb_mmap function in drivers/video/fbmem.c in the Linux kernel before 3.8.9, as used in a certain Motorola build of Android 4.1.2 and other products, allows local users to create a read-write memory mapping for the entirety of kernel memory, and consequently gain privileges, via crafted /dev/graphics/fb0 mmap2 system calls, as demonstrated by the Motochopper pwn program.

  • Published: Apr 13, 2013
  • Updated: Jun 29, 2024
  • CVE: CVE-2013-2596
  • Severity: High
  • Exploit:

CVSS v3:

  • Severity: High
  • Score: 7.8
  • AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CVSS v2:

  • Severity: Medium
  • Score: 6.9
  • AV:L/AC:M/Au:N/C:C/I:C/A:C
Software From Fixed in
motorola / android 4.1.2 4.1.2.x
linux / linux_kernel 2.6.12 3.0.75
linux / linux_kernel 3.1 3.2.45
linux / linux_kernel 3.3 3.4.42
linux / linux_kernel 3.5 3.8.9