CVE-2013-2595 is a privilege escalation vulnerability in the MSM camera driver for the Linux kernel 2.6.x and 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices. The vulnerability arises from the device-initialization functionality enabling MSM_CAM_IOCTL_SET_MEM_MAP_INFO ioctl calls to provide an unrestricted mmap interface. This allows attackers to map arbitrary physical memory into user space, enabling crafted applications to gain elevated privileges on the device.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains a proof-of-concept (POC) local exploit targeting the Qualcomm MSM camera driver on Android devices. The main code is in 'msm_cameraconfig.c' and 'msm_cameraconfig.h', which together provide functions to map kernel memory into user space and write arbitrary values to kernel addresses by abusing the /dev/msm_camera/config0 device node. The exploit works by opening /dev/video0 and /dev/msm_camera/config0, using an ioctl to set up a memory mapping, and then mapping a region of kernel memory into user space. The code includes primitives for writing to arbitrary kernel addresses, which could be used to escalate privileges or execute code in kernel context. The exploit requires local access and sufficient privileges to open the relevant device nodes. No specific CVE is referenced, but the exploit is relevant to Android devices with the vulnerable MSM camera driver. The repository is structured with a Makefile for building a static library, a README referencing the original author, and the main exploit logic in C source and header files.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.