CVE-2013-6282: Linux Kernel Improper Input Validation Vulnerability

High severity, CVSS 8.8. Actively exploited: in CISA KEV since 2022-09-15. EPSS: 39.7% chance of exploitation in the next 30 days.

The (1) get_user and (2) put_user API functions in the Linux kernel before 3.5.5 on the v6k and v7 ARM platforms do not validate certain addresses, which allows attackers to read or modify the contents of arbitrary kernel memory locations via a crafted application, as exploited in the wild against Android devices in October and November 2013.

Affected products

  • Linux Linux Kernel: before 3.2.54 (fixed in 3.2.54); from 3.3, before 3.4.12 (fixed in 3.4.12); from 3.5, before 3.5.5 (fixed in 3.5.5)

Published 2013-11-20. Last modified 2026-06-17.