Vulnerability record · CVE-2013-2596 · published 13 April 2013
CVE-2013-2596: Linux kernel fb_mmap integer overflow allows full kernel memory mapping
Linux · Linux Kernel
An integer overflow in the fb_mmap function in drivers/video/fbmem.c in the Linux kernel before 3.8.9 lets a local user create a read-write mapping of all kernel memory through crafted /dev/graphics/fb0 mmap2 calls. The flaw was used in the Motochopper Android root program and affects a Motorola build of Android 4.1.2 among other products. Because it grants full kernel memory access, it is a direct privilege-escalation primitive.
Description
Integer overflow in the fb_mmap function in drivers/video/fbmem.c in the Linux kernel before 3.8.9, as used in a certain Motorola build of Android 4.1.2 and other products, allows local users to create a read-write memory mapping for the entirety of kernel memory, and consequently gain privileges, via crafted /dev/graphics/fb0 mmap2 system calls, as demonstrated by the Motochopper pwn program.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityIt is a local privilege-escalation flaw with public exploit code and KEV listing, but it requires local access and is fixed in kernel 3.8.9 and vendor updates.
What it is
An integer overflow in the fb_mmap function in drivers/video/fbmem.c in the Linux kernel before 3.8.9 lets a local user create a read-write mapping of all kernel memory through crafted /dev/graphics/fb0 mmap2 calls. The flaw was used in the Motochopper Android root program and affects a Motorola build of Android 4.1.2 among other products. Because it grants full kernel memory access, it is a direct privilege-escalation primitive.
Impact
A local attacker gains read-write access to the entirety of kernel memory, which allows privilege escalation to root and full control of the device or host. This defeats kernel-level isolation and can be used to disable security controls or persist.
Attack surface
Reached locally by an unprivileged user who can open /dev/graphics/fb0 and issue crafted mmap2 system calls; no network access or user interaction is required. The CVSS vector confirms local access with low privileges and no UI.
Exploitation
CISA added it to KEV on 2022-09-15 with a 2022-10-06 due date, and multiple references are tagged Exploit, including the Motochopper pwn program; EPSS 30-day probability is 0.03212 (87.5th percentile). No ransomware campaign use is documented.
What to do
- Apply the Linux kernel 3.8.9 or later update, or the vendor backport for your distribution (Red Hat, Oracle, Mandriva, Juniper advisories referenced).
- For Android devices, apply the vendor firmware update that includes the kernel fix; if unavailable, restrict or remove access to /dev/graphics/fb0 for untrusted apps.
- Restrict local shell and app access on affected systems and remove unnecessary local user accounts.
- Monitor vendor advisories for the specific product build, since affected versions vary by vendor and Android build.
Detection
- Audit and alert on mmap2 calls against /dev/graphics/fb0 with unusually large length or offset values.
- Monitor for local privilege-escalation behavior consistent with Motochopper or similar root tools on Android devices.
- Track kernel version and patch level against the 3.8.9 fix and vendor backports to identify unpatched hosts.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2013-2596 to the Known Exploited Vulnerabilities catalog on 15 September 2022 as "Linux Kernel Integer Overflow Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 6 October 2022.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2013-2596 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2013-2596), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.