CVE-2013-2595

EXPLOITED

Linux kernel 2.6.x-3.x - Privilege Escalation

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2013-2595 has been observed exploited in the wild (reported by VulnCheck KEV). EIP tracks 1 public exploit from researchers including fi01.

AI-analyzed exploit summary This exploit targets a vulnerability in the Qualcomm MSM camera driver (CVE-2013-2595) by leveraging improper memory mapping to achieve arbitrary kernel memory read/write. It maps kernel memory via ioctl calls to /dev/msm_camera/config0 and /dev/video0, enabling privilege escalation.

Description

The device-initialization functionality in the MSM camera driver for the Linux kernel 2.6.x and 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, enables MSM_CAM_IOCTL_SET_MEM_MAP_INFO ioctl calls for an unrestricted mmap interface, which allows attackers to gain privileges via a crafted application.

Exploits (1)

nomisec WORKING POC 8 stars
by fi01 · local
https://github.com/fi01/libmsm_cameraconfig_exploit

This exploit targets a vulnerability in the Qualcomm MSM camera driver (CVE-2013-2595) by leveraging improper memory mapping to achieve arbitrary kernel memory read/write. It maps kernel memory via ioctl calls to /dev/msm_camera/config0 and /dev/video0, enabling privilege escalation.

Classification
Working Poc 90%
Attack Type
Lpe
Complexity
Moderate
Reliability
Reliable
Target: Qualcomm MSM camera driver (Linux kernel module)
No auth needed
Prerequisites: Access to /dev/video0 and /dev/msm_camera/config0 · Kernel memory layout detection via /proc/cpuinfo or /proc/iomem
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (1)

Core 1

Scores

EPSS 0.0089
EPSS Percentile 54.7%

Details

VulnCheck KEV 2018-01-16
CWE
CWE-264
Status published
Products (50)
codeaurora/android-msm 2.6.29
codeaurora/android-msm 3.2.54
codeaurora/android-msm 3.2.55
codeaurora/android-msm 3.2.56
codeaurora/android-msm 3.2.57
codeaurora/android-msm 3.2.58
codeaurora/android-msm 3.2.59
codeaurora/android-msm 3.2.60
codeaurora/android-msm 3.2.61
codeaurora/android-msm 3.2.62
... and 40 more
Published Aug 31, 2014
Tracked Since Feb 18, 2026