CVE-2013-2094
Linux Kernel Privilege Escalation Vulnerability
- Published
- May 14, 2013
- Updated
- Oct 22, 2025
- Assigning CNA
- redhat
- Evidence observed
- May 14, 2013
Primary CVSS
nvd · CVSS 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HModerate · next 30 days
- Percentile
- 98.8%
- Model date
- Sep 21, 2026
EPSS is a statistical estimate, not a certainty or a measure of impact. Combine it with CVSS, KEV status, exposure and your environment.
CISA Known Exploited
This CVE appears in the CISA Known Exploited Vulnerabilities catalog.
Summary
The perf_swevent_init function in kernel/events/core.c in the Linux kernel before 3.8.9 uses an incorrect integer data type, which allows local users to gain privileges via a crafted perf_event_open system call.
Sources
12- CVE-2013-2094Exploit
Standalone C exploit for Linux kernel CVE-2013-2094, targeting a perf_event_open integer overflow to escalate privileges to root on affected systems.
- cve-2013-2094Exploit
original cve-2013-2094 exploit and a rewritten version for educational purposes
- fix-cve-2013-2094Patch
Generates portable SystemTap kernel modules to mitigate CVE-2013-2094 on Enterprise Linux systems, with automated build and deployment scripts for runtime patching.
Responsible use
Use vulnerability information only on systems you own or are authorized to test. Kitploit links to public research metadata and does not store exploit code or malicious payloads.