CVE-2013-2094

HIGH KEV

Linux Kernel < 3.0.75 - Numeric Error

Title source: rule

Description

The perf_swevent_init function in kernel/events/core.c in the Linux kernel before 3.8.9 uses an incorrect integer data type, which allows local users to gain privileges via a crafted perf_event_open system call.

Exploits (11)

exploitdb WORKING POC VERIFIED
by Vitaly Nikolenko · clocallinux_x86-64
https://www.exploit-db.com/exploits/33589
exploitdb WORKING POC VERIFIED
by Andrea Bittau · clocallinux_x86-64
https://www.exploit-db.com/exploits/26131
exploitdb WORKING POC
by sd · clocallinux
https://www.exploit-db.com/exploits/25444
nomisec WORKING POC 91 stars
by realtalk · local
https://github.com/realtalk/cve-2013-2094
nomisec WORKING POC 16 stars
by hiikezoe · local
https://github.com/hiikezoe/libperf_event_exploit
nomisec WORKING POC 4 stars
by Pashkela · poc
https://github.com/Pashkela/CVE-2013-2094
nomisec WORKING POC 3 stars
by timhsutw · remote
https://github.com/timhsutw/cve-2013-2094
nomisec WORKING POC 1 stars
by vnik5287 · remote
https://github.com/vnik5287/CVE-2013-2094
nomisec WORKING POC
by letsr00t · poc
https://github.com/letsr00t/CVE-2013-2094
nomisec WORKING POC
by tarunyadav · poc
https://github.com/tarunyadav/fix-cve-2013-2094

References (30)

... and 10 more

Scores

CVSS v3 8.4
EPSS 0.6585
EPSS Percentile 98.5%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CISA KEV 2022-09-15
VulnCheck KEV 2013-05-17
InTheWild.io 2013-05-17
ENISA EUVD EUVD-2013-2068
CWE
CWE-189
Status published
Products (1)
linux/linux_kernel < 3.0.75
Published May 14, 2013
KEV Added Sep 15, 2022
Tracked Since Feb 18, 2026