CVE-2013-2094
Linux Kernel ≤ 3.0.75
Raw vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HSummary
CVE-2013-2094 is a high-severity an unspecified weakness vulnerability in Linux Linux Kernel. Its CVSS base score is 8.4 (High).
Operationally, ranked in the top 1% of CVEs by exploit likelihood; CISA has added it to the Known Exploited Vulnerabilities catalog; a public proof-of-concept is referenced.
Deeper analysis AI-assisted summary
Synthesised by an AI model from the NVD description and linked references — a reading aid, not an authoritative source.
The vulnerability is an integer type handling flaw in the perf_swevent_init function located in kernel/events/core.c of the Linux kernel prior to version 3.8.9. It stems from use of an incorrect data type when processing inputs to the perf_event_open system call and is tracked under CWE-189 with a CVSS score of 8.4.
Local users can exploit the issue by supplying a crafted perf_event_open call, resulting in privilege escalation that grants full control over the system with impacts to confidentiality, integrity, and availability.
Upstream remediation is provided by the referenced kernel commit, while distribution advisories for CentOS and openSUSE detail the availability of updated packages that address the flaw through backported fixes.
EU & UK References
- 🇪🇺 ENISA EUVD: EUVD-2013-2068
Vulnerability Data
The perf_swevent_init function in kernel/events/core.c in the Linux kernel before 3.8.9 uses an incorrect integer data type, which allows local users to gain privileges via a crafted perf_event_open system call.
- CWE(s)
- KEV Date Added
- 15 September 2022
Related Threats
CVEs Like This One
Affected Assets
Mitigating Controls
No mitigating controls mapped yet. The per-CVE control annotator has not reached this CVE.