The (1) get_user and (2) put_user API functions in the Linux kernel before 3.5.5 on the v6k and v7 ARM platforms do not validate certain addresses, which allows attackers to read or modify the contents of arbitrary kernel memory locations via a crafted application, as exploited in the wild against Android devices in October and November 2013.
Conclusion & alert: CVE-2013-6282 is rated Critical Active Threat (89.7/100): CVSS High severity, with high exploitation likelihood (EPSS 39.71%, 98th percentile). Core evidence: CISA KEV confirms active exploitation (added 2022-09-15) affecting Linux / Kernel. a weakness (CWE-20) Unauthenticated remote administrative access may be possible. Mandatory action: The CISA remediation deadline has passed—treat as an emergency patch priority.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
: Linux Kernel Improper Input Validation Vulnerability · CISA KEV detail
: 2022-09-15
: 2022-10-06
: Apply updates per vendor instructions.
| EDB-ID | Source | Kind | Published | Link |
|---|---|---|---|---|
| 40975 | exploit_db | edb | 2016-12-29 | Exploit-DB ↗ |
| 31574 | exploit_db | edb | 2014-02-11 | Exploit-DB ↗ |
| — | nvd_ref | exploit_tag | Exploit-DB ↗ | |
| — | nvd_ref | exploit_tag | Exploit-DB ↗ |
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 67.65% | 39.71% | -27.94% |
| 2 | 2026-06-04 | 68.16% | 67.65% | -0.51% |
| 3 | 2026-05-08 | — | 68.16% | — |
Full EPSS history (30 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 8.8 | 3.1 | HIGH |
|
2.8 | 5.9 | [email protected] |
| 8.8 | 3.1 | HIGH |
|
2.8 | 5.9 | 134c704f-9b21-4f2e-91b3-4a467353bcc0 |
| 7.2 | 2.0 | HIGH |
|
3.9 | 10.0 | [email protected] |
| vendor | priority | summary | link |
|---|---|---|---|
debian
|
not yet assigned | CVE-2013-6282 not yet assigned priority: Debian including 1 source packages (linux), 5 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 5. | https://security-tracker.debian.org/tracker/CVE-2013-6282 |
redhat
|
— | — | https://access.redhat.com/security/cve/CVE-2013-6282 |
ubuntu
|
medium | CVE-2013-6282 medium priority: Ubuntu including 30 source packages (linux, linux-armadaxp, …), 327 status rows across 13 suites (lucid, precise, quantal, raring, saucy, trusty, upstream, utopic, vivid, wily, xenial, yakkety, zesty): DNE 228, not-affected 40, released 32, ignored 27. | https://ubuntu.com/security/CVE-2013-6282 |
: AV:L per https://www.codeaurora.org/projects/security-advisories/missing-access-checks-putusergetuser-kernel-api-cve-2013-6282
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| linux | linux_kernel | < 3.2.54 | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
| linux | linux_kernel | >= 3.3, < 3.4.12 | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
| linux | linux_kernel | >= 3.5, < 3.5.5 | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
| URL | Tags |
|---|---|
| http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=8404663f81d212918ff85f493649a7991209fa04 | Patch |
| http://www.codeaurora.org/projects/security-advisories/missing-access-checks-putusergetuser-kernel-api-cve-2013-6282 | Patch |
| http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.5.5 | Mailing List Vendor Advisory |
| http://www.openwall.com/lists/oss-security/2013/11/14/11 | Mailing List |
| http://www.securityfocus.com/bid/63734 | Third Party Advisory VDB Entry |
| http://www.ubuntu.com/usn/USN-2067-1 | Third Party Advisory VDB Entry |
| https://github.com/torvalds/linux/commit/8404663f81d212918ff85f493649a7991209fa04 | Exploit Patch |
| https://www.exploit-db.com/exploits/40975/ | Exploit Third Party Advisory VDB Entry |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2013-6282 | US Government Resource |