Stack-based buffer overflow in the acdb_ioctl function in audio_acdb.c in the acdb audio driver for the Linux kernel 2.6.x and 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, allows attackers to gain privileges via an application that leverages /dev/msm_acdb access and provides a large size value in an ioctl argument.
Conclusion & alert: CVE-2013-2597 is rated Active Exploitation (78.8/100): CVSS High severity, with medium exploitation likelihood (EPSS 1.50%). Core evidence: CISA KEV confirms active exploitation (added 2022-09-15) affecting Code Aurora / ACDB Audio Driver. a weakness (CWE-121) Unauthenticated remote administrative access may be possible. Mandatory action: The CISA remediation deadline has passed—treat as an emergency patch priority.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
: Code Aurora ACDB Audio Driver Stack-based Buffer Overflow Vulnerability · CISA KEV detail
: 2022-09-15
: 2022-10-06
: Apply updates per vendor instructions.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 6.10% | 1.50% | -4.60% |
| 2 | 2026-04-23 | 6.74% | 6.10% | -0.64% |
| 3 | 2025-10-22 | — | 6.74% | — |
Full EPSS history (19 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 8.4 | 3.1 | HIGH |
|
2.5 | 5.9 | 134c704f-9b21-4f2e-91b3-4a467353bcc0 |
| 7.2 | 2.0 | HIGH |
|
3.9 | 10.0 | [email protected] |
| vendor | priority | summary | link |
|---|---|---|---|
redhat
|
— | — | https://access.redhat.com/security/cve/CVE-2013-2597 |
ubuntu
|
medium | CVE-2013-2597 medium priority: Ubuntu including 23 source packages (linux, linux-armadaxp, …), 159 status rows across 7 suites (lucid, precise, trusty, upstream, utopic, vivid, wily): DNE 102, not-affected 49, ignored 8. | https://ubuntu.com/security/CVE-2013-2597 |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| codeaurora | android-msm | 2.6.29 | cpe:2.3:o:codeaurora:android-msm:2.6.29:*:*:*:*:*:*:* |
| codeaurora | android-msm | 3.2.54 | cpe:2.3:o:codeaurora:android-msm:3.2.54:*:*:*:*:*:*:* |
| codeaurora | android-msm | 3.2.55 | cpe:2.3:o:codeaurora:android-msm:3.2.55:*:*:*:*:*:*:* |
| codeaurora | android-msm | 3.2.56 | cpe:2.3:o:codeaurora:android-msm:3.2.56:*:*:*:*:*:*:* |
| codeaurora | android-msm | 3.2.57 | cpe:2.3:o:codeaurora:android-msm:3.2.57:*:*:*:*:*:*:* |
| codeaurora | android-msm | 3.2.58 | cpe:2.3:o:codeaurora:android-msm:3.2.58:*:*:*:*:*:*:* |
| codeaurora | android-msm | 3.2.59 | cpe:2.3:o:codeaurora:android-msm:3.2.59:*:*:*:*:*:*:* |
| codeaurora | android-msm | 3.2.60 | cpe:2.3:o:codeaurora:android-msm:3.2.60:*:*:*:*:*:*:* |
| codeaurora | android-msm | 3.2.61 | cpe:2.3:o:codeaurora:android-msm:3.2.61:*:*:*:*:*:*:* |
| codeaurora | android-msm | 3.2.62 | cpe:2.3:o:codeaurora:android-msm:3.2.62:*:*:*:*:*:*:* |
| codeaurora | android-msm | 3.4.72 | cpe:2.3:o:codeaurora:android-msm:3.4.72:*:*:*:*:*:*:* |
| codeaurora | android-msm | 3.4.73 | cpe:2.3:o:codeaurora:android-msm:3.4.73:*:*:*:*:*:*:* |
| codeaurora | android-msm | 3.4.74 | cpe:2.3:o:codeaurora:android-msm:3.4.74:*:*:*:*:*:*:* |
| codeaurora | android-msm | 3.4.75 | cpe:2.3:o:codeaurora:android-msm:3.4.75:*:*:*:*:*:*:* |
| codeaurora | android-msm | 3.4.76 | cpe:2.3:o:codeaurora:android-msm:3.4.76:*:*:*:*:*:*:* |
| codeaurora | android-msm | 3.4.77 | cpe:2.3:o:codeaurora:android-msm:3.4.77:*:*:*:*:*:*:* |
| codeaurora | android-msm | 3.4.78 | cpe:2.3:o:codeaurora:android-msm:3.4.78:*:*:*:*:*:*:* |
| codeaurora | android-msm | 3.4.79 | cpe:2.3:o:codeaurora:android-msm:3.4.79:*:*:*:*:*:*:* |
| codeaurora | android-msm | 3.4.80 | cpe:2.3:o:codeaurora:android-msm:3.4.80:*:*:*:*:*:*:* |
| codeaurora | android-msm | 3.4.81 | cpe:2.3:o:codeaurora:android-msm:3.4.81:*:*:*:*:*:*:* |
| codeaurora | android-msm | 3.4.82 | cpe:2.3:o:codeaurora:android-msm:3.4.82:*:*:*:*:*:*:* |
| codeaurora | android-msm | 3.4.83 | cpe:2.3:o:codeaurora:android-msm:3.4.83:*:*:*:*:*:*:* |
| codeaurora | android-msm | 3.4.84 | cpe:2.3:o:codeaurora:android-msm:3.4.84:*:*:*:*:*:*:* |
| codeaurora | android-msm | 3.4.85 | cpe:2.3:o:codeaurora:android-msm:3.4.85:*:*:*:*:*:*:* |
| codeaurora | android-msm | 3.4.86 | cpe:2.3:o:codeaurora:android-msm:3.4.86:*:*:*:*:*:*:* |
| codeaurora | android-msm | 3.4.87 | cpe:2.3:o:codeaurora:android-msm:3.4.87:*:*:*:*:*:*:* |
| codeaurora | android-msm | 3.4.88 | cpe:2.3:o:codeaurora:android-msm:3.4.88:*:*:*:*:*:*:* |
| codeaurora | android-msm | 3.4.89 | cpe:2.3:o:codeaurora:android-msm:3.4.89:*:*:*:*:*:*:* |
| codeaurora | android-msm | 3.4.90 | cpe:2.3:o:codeaurora:android-msm:3.4.90:*:*:*:*:*:*:* |
| codeaurora | android-msm | 3.4.91 | cpe:2.3:o:codeaurora:android-msm:3.4.91:*:*:*:*:*:*:* |
| codeaurora | android-msm | 3.4.92 | cpe:2.3:o:codeaurora:android-msm:3.4.92:*:*:*:*:*:*:* |
| codeaurora | android-msm | 3.4.93 | cpe:2.3:o:codeaurora:android-msm:3.4.93:*:*:*:*:*:*:* |
| codeaurora | android-msm | 3.4.94 | cpe:2.3:o:codeaurora:android-msm:3.4.94:*:*:*:*:*:*:* |
| codeaurora | android-msm | 3.4.95 | cpe:2.3:o:codeaurora:android-msm:3.4.95:*:*:*:*:*:*:* |
| codeaurora | android-msm | 3.4.96 | cpe:2.3:o:codeaurora:android-msm:3.4.96:*:*:*:*:*:*:* |
| codeaurora | android-msm | 3.4.97 | cpe:2.3:o:codeaurora:android-msm:3.4.97:*:*:*:*:*:*:* |
| codeaurora | android-msm | 3.4.98 | cpe:2.3:o:codeaurora:android-msm:3.4.98:*:*:*:*:*:*:* |
| codeaurora | android-msm | 3.4.99 | cpe:2.3:o:codeaurora:android-msm:3.4.99:*:*:*:*:*:*:* |
| codeaurora | android-msm | 3.4.100 | cpe:2.3:o:codeaurora:android-msm:3.4.100:*:*:*:*:*:*:* |
| codeaurora | android-msm | 3.4.101 | cpe:2.3:o:codeaurora:android-msm:3.4.101:*:*:*:*:*:*:* |
| codeaurora | android-msm | 3.4.102 | cpe:2.3:o:codeaurora:android-msm:3.4.102:*:*:*:*:*:*:* |
| codeaurora | android-msm | 3.4.103 | cpe:2.3:o:codeaurora:android-msm:3.4.103:*:*:*:*:*:*:* |
| codeaurora | android-msm | 3.10 | cpe:2.3:o:codeaurora:android-msm:3.10:*:*:*:*:*:*:* |
| codeaurora | android-msm | 3.10.22 | cpe:2.3:o:codeaurora:android-msm:3.10.22:*:*:*:*:*:*:* |
| codeaurora | android-msm | 3.10.23 | cpe:2.3:o:codeaurora:android-msm:3.10.23:*:*:*:*:*:*:* |
| codeaurora | android-msm | 3.10.24 | cpe:2.3:o:codeaurora:android-msm:3.10.24:*:*:*:*:*:*:* |
| codeaurora | android-msm | 3.10.25 | cpe:2.3:o:codeaurora:android-msm:3.10.25:*:*:*:*:*:*:* |
| codeaurora | android-msm | 3.10.26 | cpe:2.3:o:codeaurora:android-msm:3.10.26:*:*:*:*:*:*:* |
| codeaurora | android-msm | 3.10.27 | cpe:2.3:o:codeaurora:android-msm:3.10.27:*:*:*:*:*:*:* |
| codeaurora | android-msm | 3.10.28 | cpe:2.3:o:codeaurora:android-msm:3.10.28:*:*:*:*:*:*:* |
| codeaurora | android-msm | 3.10.29 | cpe:2.3:o:codeaurora:android-msm:3.10.29:*:*:*:*:*:*:* |
| codeaurora | android-msm | 3.10.30 | cpe:2.3:o:codeaurora:android-msm:3.10.30:*:*:*:*:*:*:* |
| codeaurora | android-msm | 3.10.31 | cpe:2.3:o:codeaurora:android-msm:3.10.31:*:*:*:*:*:*:* |
| codeaurora | android-msm | 3.10.32 | cpe:2.3:o:codeaurora:android-msm:3.10.32:*:*:*:*:*:*:* |
| codeaurora | android-msm | 3.10.33 | cpe:2.3:o:codeaurora:android-msm:3.10.33:*:*:*:*:*:*:* |
| codeaurora | android-msm | 3.10.35 | cpe:2.3:o:codeaurora:android-msm:3.10.35:*:*:*:*:*:*:* |
| codeaurora | android-msm | 3.10.36 | cpe:2.3:o:codeaurora:android-msm:3.10.36:*:*:*:*:*:*:* |
| codeaurora | android-msm | 3.10.37 | cpe:2.3:o:codeaurora:android-msm:3.10.37:*:*:*:*:*:*:* |
| codeaurora | android-msm | 3.10.38 | cpe:2.3:o:codeaurora:android-msm:3.10.38:*:*:*:*:*:*:* |
| codeaurora | android-msm | 3.10.39 | cpe:2.3:o:codeaurora:android-msm:3.10.39:*:*:*:*:*:*:* |
| codeaurora | android-msm | 3.10.40 | cpe:2.3:o:codeaurora:android-msm:3.10.40:*:*:*:*:*:*:* |
| codeaurora | android-msm | 3.10.41 | cpe:2.3:o:codeaurora:android-msm:3.10.41:*:*:*:*:*:*:* |
| codeaurora | android-msm | 3.10.42 | cpe:2.3:o:codeaurora:android-msm:3.10.42:*:*:*:*:*:*:* |
| codeaurora | android-msm | 3.10.43 | cpe:2.3:o:codeaurora:android-msm:3.10.43:*:*:*:*:*:*:* |
| codeaurora | android-msm | 3.10.44 | cpe:2.3:o:codeaurora:android-msm:3.10.44:*:*:*:*:*:*:* |
| codeaurora | android-msm | 3.10.45 | cpe:2.3:o:codeaurora:android-msm:3.10.45:*:*:*:*:*:*:* |
| codeaurora | android-msm | 3.10.46 | cpe:2.3:o:codeaurora:android-msm:3.10.46:*:*:*:*:*:*:* |
| codeaurora | android-msm | 3.10.47 | cpe:2.3:o:codeaurora:android-msm:3.10.47:*:*:*:*:*:*:* |
| codeaurora | android-msm | 3.10.48 | cpe:2.3:o:codeaurora:android-msm:3.10.48:*:*:*:*:*:*:* |
| codeaurora | android-msm | 3.10.49 | cpe:2.3:o:codeaurora:android-msm:3.10.49:*:*:*:*:*:*:* |
| codeaurora | android-msm | 3.10.50 | cpe:2.3:o:codeaurora:android-msm:3.10.50:*:*:*:*:*:*:* |
| codeaurora | android-msm | 3.10.51 | cpe:2.3:o:codeaurora:android-msm:3.10.51:*:*:*:*:*:*:* |
| codeaurora | android-msm | 3.10.52 | cpe:2.3:o:codeaurora:android-msm:3.10.52:*:*:*:*:*:*:* |
| codeaurora | android-msm | 3.10.53 | cpe:2.3:o:codeaurora:android-msm:3.10.53:*:*:*:*:*:*:* |
| codeaurora | android-msm | 3.12.3 | cpe:2.3:o:codeaurora:android-msm:3.12.3:*:*:*:*:*:*:* |
| codeaurora | android-msm | 3.12.4 | cpe:2.3:o:codeaurora:android-msm:3.12.4:*:*:*:*:*:*:* |
| codeaurora | android-msm | 3.12.5 | cpe:2.3:o:codeaurora:android-msm:3.12.5:*:*:*:*:*:*:* |
| codeaurora | android-msm | 3.12.6 | cpe:2.3:o:codeaurora:android-msm:3.12.6:*:*:*:*:*:*:* |
| codeaurora | android-msm | 3.12.7 | cpe:2.3:o:codeaurora:android-msm:3.12.7:*:*:*:*:*:*:* |
| codeaurora | android-msm | 3.12.8 | cpe:2.3:o:codeaurora:android-msm:3.12.8:*:*:*:*:*:*:* |
| URL | Tags |
|---|---|
| https://www.codeaurora.org/projects/security-advisories/stack-based-buffer-overflow-acdb-audio-driver-cve-2013-2597 | Broken Link Vendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2013-2597 | US Government Resource |