Cyber Resilience

CVE-2013-2094

Linux Kernel ≤ 3.0.75

CISA KEVActive ExploitationEUVD ExploitedPublic PoC
Published
14 May 2013
Modified
22 April 2026
KEV Added
15 September 2022
Patch / advisory
CVSS Score v3.1 8.4
Click a component to see what it means
Raw vectorCVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score 0.48 99th percentile
Risk Priority 88 floored blend · peak EPSS

Summary

CVE-2013-2094 is a high-severity an unspecified weakness vulnerability in Linux Linux Kernel. Its CVSS base score is 8.4 (High).

Operationally, ranked in the top 1% of CVEs by exploit likelihood; CISA has added it to the Known Exploited Vulnerabilities catalog; a public proof-of-concept is referenced.

Deeper analysis AI-assisted summary

Synthesised by an AI model from the NVD description and linked references — a reading aid, not an authoritative source.

The vulnerability is an integer type handling flaw in the perf_swevent_init function located in kernel/events/core.c of the Linux kernel prior to version 3.8.9. It stems from use of an incorrect data type when processing inputs to the perf_event_open system call and is tracked under CWE-189 with a CVSS score of 8.4.

Local users can exploit the issue by supplying a crafted perf_event_open call, resulting in privilege escalation that grants full control over the system with impacts to confidentiality, integrity, and availability.

Upstream remediation is provided by the referenced kernel commit, while distribution advisories for CentOS and openSUSE detail the availability of updated packages that address the flaw through backported fixes.

EU & UK References

Vulnerability Data

The perf_swevent_init function in kernel/events/core.c in the Linux kernel before 3.8.9 uses an incorrect integer data type, which allows local users to gain privileges via a crafted perf_event_open system call.

CWE(s)
KEV Date Added
15 September 2022

Related Threats

CVEs Like This One

CVE-2013-6282Same product: Linux Linux Kernelboth on KEV
CVE-2024-49994Same product: Linux Linux Kernel
CVE-2024-39509Same product: Linux Linux Kernel
CVE-2024-40969Same product: Linux Linux Kernel
CVE-2024-50238Same product: Linux Linux Kernel
CVE-2024-43863Same product: Linux Linux Kernel
CVE-2024-53147Same product: Linux Linux Kernel
CVE-2024-50056Same product: Linux Linux Kernel
CVE-2024-35841Same product: Linux Linux Kernel
CVE-2024-44958Same product: Linux Linux Kernel

Affected Assets

linux
linux kernel
≤ 3.0.75 · 3.1 — 3.2.45 · 3.3 — 3.4.42

Mitigating Controls

No mitigating controls mapped yet. The per-CVE control annotator has not reached this CVE.

References