CVE-2013-2094
HIGH KEVLinux Kernel < 3.0.75 - Numeric Error
Title source: ruleDescription
The perf_swevent_init function in kernel/events/core.c in the Linux kernel before 3.8.9 uses an incorrect integer data type, which allows local users to gain privileges via a crafted perf_event_open system call.
Exploits (11)
exploitdb
WORKING POC
VERIFIED
by Vitaly Nikolenko · clocallinux_x86-64
https://www.exploit-db.com/exploits/33589
exploitdb
WORKING POC
VERIFIED
by Andrea Bittau · clocallinux_x86-64
https://www.exploit-db.com/exploits/26131
References (30)
Scores
CVSS v3
8.4
EPSS
0.6585
EPSS Percentile
98.5%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CISA KEV
2022-09-15
VulnCheck KEV
2013-05-17
InTheWild.io
2013-05-17
ENISA EUVD
EUVD-2013-2068
CWE
CWE-189
Status
published
Products (1)
linux/linux_kernel
< 3.0.75
Published
May 14, 2013
KEV Added
Sep 15, 2022
Tracked Since
Feb 18, 2026