← Vulnerability feed

Vulnerability record · CVE-2013-2596 · published 13 April 2013

CVE-2013-2596: Linux kernel fb_mmap integer overflow allows full kernel memory mapping

Linux · Linux Kernel

An integer overflow in the fb_mmap function in drivers/video/fbmem.c in the Linux kernel before 3.8.9 lets a local user create a read-write mapping of all kernel memory through crafted /dev/graphics/fb0 mmap2 calls. The flaw was used in the Motochopper Android root program and affects a Motorola build of Android 4.1.2 among other products. Because it grants full kernel memory access, it is a direct privilege-escalation primitive.

7.8 CVSS 3.1 High CISA KEV since 15 Sep 2022 EPSS 3.2% · top 12.3% CWE-190 · Integer overflow
7.8CVSS 3.1 base score, v2 6.9
3.2%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
2Affected product versions listed by NVD
33References, 8 tagged exploit
16 Jun 2026Last modified by NVD

Description

Integer overflow in the fb_mmap function in drivers/video/fbmem.c in the Linux kernel before 3.8.9, as used in a certain Motorola build of Android 4.1.2 and other products, allows local users to create a read-write memory mapping for the entirety of kernel memory, and consequently gain privileges, via crafted /dev/graphics/fb0 mmap2 system calls, as demonstrated by the Motochopper pwn program.

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

high priorityIt is a local privilege-escalation flaw with public exploit code and KEV listing, but it requires local access and is fixed in kernel 3.8.9 and vendor updates.

What it is

An integer overflow in the fb_mmap function in drivers/video/fbmem.c in the Linux kernel before 3.8.9 lets a local user create a read-write mapping of all kernel memory through crafted /dev/graphics/fb0 mmap2 calls. The flaw was used in the Motochopper Android root program and affects a Motorola build of Android 4.1.2 among other products. Because it grants full kernel memory access, it is a direct privilege-escalation primitive.

Impact

A local attacker gains read-write access to the entirety of kernel memory, which allows privilege escalation to root and full control of the device or host. This defeats kernel-level isolation and can be used to disable security controls or persist.

Attack surface

Reached locally by an unprivileged user who can open /dev/graphics/fb0 and issue crafted mmap2 system calls; no network access or user interaction is required. The CVSS vector confirms local access with low privileges and no UI.

Exploitation

CISA added it to KEV on 2022-09-15 with a 2022-10-06 due date, and multiple references are tagged Exploit, including the Motochopper pwn program; EPSS 30-day probability is 0.03212 (87.5th percentile). No ransomware campaign use is documented.

What to do

  • Apply the Linux kernel 3.8.9 or later update, or the vendor backport for your distribution (Red Hat, Oracle, Mandriva, Juniper advisories referenced).
  • For Android devices, apply the vendor firmware update that includes the kernel fix; if unavailable, restrict or remove access to /dev/graphics/fb0 for untrusted apps.
  • Restrict local shell and app access on affected systems and remove unnecessary local user accounts.
  • Monitor vendor advisories for the specific product build, since affected versions vary by vendor and Android build.

Detection

  • Audit and alert on mmap2 calls against /dev/graphics/fb0 with unusually large length or offset values.
  • Monitor for local privilege-escalation behavior consistent with Motochopper or similar root tools on Android devices.
  • Track kernel version and patch level against the 3.8.9 fix and vendor backports to identify unpatched hosts.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2013-2596 to the Known Exploited Vulnerabilities catalog on 15 September 2022 as "Linux Kernel Integer Overflow Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 6 October 2022.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://forum.xda-developers.com/showthread.php?t=2255491 Exploit
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=b4cbb197c7e7a68dbad0d491242e3ca67420c13e Broken Link
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=fc9bbca8f650e5f738af8806317c0a041a48ae4a Broken Link
http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10761 Third Party Advisory
http://marc.info/?l=linux-kernel&m=136616837923938&w=2 Mailing ListPatchThird Party Advisory
http://rhn.redhat.com/errata/RHSA-2015-0695.html Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2015-0782.html Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2015-0803.html Third Party Advisory
http://www.droid-life.com/2013/04/09/root-method-released-for-droid-razr-hd-running-android-4-1-2-other-devices-too/ ExploitIssue TrackingThird Party Advisory
http://www.droidrzr.com/index.php/topic/15208-root-motochopper-yet-another-android-root-exploit/ ExploitIssue Tracking
http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.8.9 Mailing ListRelease Notes
http://www.mandriva.com/security/advisories?name=MDVSA-2013:176 Broken Link
http://www.oracle.com/technetwork/topics/security/linuxbulletinjan2016-2867209.html PatchThird Party Advisory
http://www.securityfocus.com/bid/59264 Broken LinkThird Party AdvisoryVDB Entry
https://github.com/torvalds/linux/commit/b4cbb197c7e7a68dbad0d491242e3ca67420c13e Patch
https://github.com/torvalds/linux/commit/fc9bbca8f650e5f738af8806317c0a041a48ae4a ExploitPatch
http://forum.xda-developers.com/showthread.php?t=2255491 Exploit
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=b4cbb197c7e7a68dbad0d491242e3ca67420c13e Broken Link
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=fc9bbca8f650e5f738af8806317c0a041a48ae4a Broken Link
http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10761 Third Party Advisory
http://marc.info/?l=linux-kernel&m=136616837923938&w=2 Mailing ListPatchThird Party Advisory
http://rhn.redhat.com/errata/RHSA-2015-0695.html Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2015-0782.html Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2015-0803.html Third Party Advisory
http://www.droid-life.com/2013/04/09/root-method-released-for-droid-razr-hd-running-android-4-1-2-other-devices-too/ ExploitIssue TrackingThird Party Advisory
http://www.droidrzr.com/index.php/topic/15208-root-motochopper-yet-another-android-root-exploit/ ExploitIssue Tracking
http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.8.9 Mailing ListRelease Notes
http://www.mandriva.com/security/advisories?name=MDVSA-2013:176 Broken Link
http://www.oracle.com/technetwork/topics/security/linuxbulletinjan2016-2867209.html PatchThird Party Advisory
http://www.securityfocus.com/bid/59264 Broken LinkThird Party AdvisoryVDB Entry
https://github.com/torvalds/linux/commit/b4cbb197c7e7a68dbad0d491242e3ca67420c13e Patch
https://github.com/torvalds/linux/commit/fc9bbca8f650e5f738af8806317c0a041a48ae4a ExploitPatch
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2013-2596 US Government Resource

Track CVE-2013-2596 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2025-39682Linux kernel TLS zero-length record handling flaw on rx_listThe Linux kernel TLS receive path mishandles zero-length records that arrive from the rx_list, breaking the assumption that a record type change cann…KEVEPSS 2.9%analysed8.8CVE-2026-53266Linux kernel ebtables SNAT out-of-bounds write in ARP rewriteThe ebtables SNAT target rewrites the ARP sender hardware address via skb_store_bits() without first making that range writable. When the ARP SHA byt…KEVEPSS 0.65%analysed8.8CVE-2023-3079Google Chrome V8 type confusion enables heap corruptionCVE-2023-3079 is a type confusion flaw in the V8 JavaScript engine in Google Chrome before 114.0.5735.110. A crafted HTML page can trigger the confus…KEVEPSS 32%analysed8.8CVE-2013-6282Linux kernel ARM get_user/put_user missing address validationThe get_user and put_user API functions in the Linux kernel before 3.5.5 on v6k and v7 ARM platforms fail to validate certain addresses, allowing cra…KEVEPSS 40%analysed8.4CVE-2022-0185Linux Kernel Filesystem Context Heap Buffer OverflowThe legacy_parse_param function in the Linux kernel's Filesystem Context functionality fails to properly verify supplied parameter lengths, causing a…KEVEPSS 25%analysed8.4CVE-2013-2094Linux Kernel perf_swevent_init Integer Type Flaw Enables Local Privilege EscalationThe perf_swevent_init function in kernel/events/core.c in the Linux kernel before 3.8.9 uses an incorrect integer data type, allowing a local user to…KEVEPSS 48%analysed7.8CVE-2026-53362Linux kernel IPv6 UDP paged allocation out-of-bounds write__ip6_append_data() in the Linux kernel mis-accounts fraggap on the paged-allocation path, leaving the linear skb area undersized while pagedlen is o…KEVEPSS 0.71%analysed7.8CVE-2026-31431Linux kernel algif_aead in-place crypto operation flawThe Linux kernel's algif_aead AF_ALG AEAD interface operated in-place on buffers that come from different mappings, a flaw the fix resolves by revert…KEVEPSS 3.4%analysed

Source: NIST National Vulnerability Database (record CVE-2013-2596), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.