← Global Threat Landscape

CVE-2013-6282

CWE-20

Critical

97.2

RPS

Description

The (1) get_user and (2) put_user API functions in the Linux kernel before 3.5.5 on the v6k and v7 ARM platforms do not validate certain addresses, which allows attackers to read or modify the contents of arbitrary kernel memory locations via a crafted application, as exploited in the wild against Android devices in October and November 2013.

Source: NVD

Signals

CVSS
8.8
High · v3.1
EPSS
39.71%
Probability of exploitation in the next 30 days (FIRST)
CISA KEV
In CISA KEV since Sept 2022
Fix commit
Fix commit known
Sources: MoreFixes, FreshFixes
Weakness
CWE-20
Published
20 Nov 2013
Last modified 22 Apr 2026

How to read these signals: RPS · EPSS · CISA KEV · Data sources

Get this score from the API

curl -H "Authorization: Bearer dsec_live_xxxxxxxx" \
  https://api.intelligence.devsecure.io/api/v1/rps/CVE-2013-6282

Replace the placeholder with your key. Get a free API key or rank your own CVEs.

Data as of 7 Oct 2026, 05:16 UK time

CVE-2013-6282 · RPS 97.2 · DevSecure Intelligence