CVE-2013-6282 is a privilege escalation vulnerability in the Linux kernel (before 3.5.5) affecting ARM v6k and v7 platforms. The vulnerability arises from the get_user and put_user API functions failing to properly validate user-supplied addresses, allowing unprivileged userspace applications to read from or write to arbitrary kernel memory locations. This flaw enables attackers to bypass kernel memory protections and execute code with kernel privileges. The vulnerability was actively exploited in the wild, notably by Android malware such as Skygofree, to gain root access on targeted devices.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
5 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This repository contains a single Metasploit module: 'modules/exploits/android/local/put_user_vroot.rb'. The module exploits a vulnerability (CVE-2013-6282) in the get_user and put_user API functions of the Linux kernel prior to version 3.5.5, affecting Android and Linux devices. The exploit leverages missing checks in these functions to read and write kernel memory, allowing an unprivileged user to escalate privileges to root (uid 0). The module works by reading kernel memory to locate critical function addresses, then injecting and executing a payload (by default, a meterpreter reverse TCP shell) as root. The exploit is operational and weaponized, as it is part of the Metasploit framework and supports customizable payloads. The only fingerprintable endpoint is the local file 'CVE-2013-6282.so', which is used as the exploit payload. The module is intended for use in post-exploitation scenarios where the attacker already has code execution on the target device.
This repository contains a local privilege escalation exploit targeting specific Samsung Galaxy S4 Android devices (ATT SGH-I337 MK2 and VZW SGH-I545 MJ7/MK2) vulnerable to CVE-2013-6282. The main file, 'bypasslkm.c', is a C program that uses ptrace to write a value to a hardcoded kernel memory address, effectively patching the kernel to bypass the signature verification for kernel modules. This allows unsigned kernel modules to be loaded, which can be leveraged for further exploitation or persistence. The program can also restore the original kernel value if run with the '-r' argument. The Makefile is used to compile the exploit for ARM Android targets. The exploit requires local access and sufficient privileges to execute native code and interact with kernel memory. No network endpoints are present; all actions are performed locally on the device.
This repository contains a proof-of-concept (POC) exploit for CVE-2013-6282, a vulnerability in the Android kernel that allows local attackers to read arbitrary kernel memory from user space. The main exploit logic is implemented in 'get_user.c', which defines a function that uses a TCP socket and manipulates the IP_TTL socket option via setsockopt and getsockopt to read values from arbitrary kernel addresses. The exploit is structured as a static library (as defined in 'Android.mk'), making it suitable for integration into other projects or for further development. There are no hardcoded network endpoints or external targets; the exploit operates entirely locally on the vulnerable device. The README succinctly states the purpose of the library. The code is written in C and is intended to be compiled for Android systems. The exploit does not provide a shell or privilege escalation directly, but rather enables kernel memory disclosure, which can be a building block for further exploitation.
This repository contains a local privilege escalation exploit for Android devices vulnerable to CVE-2013-6282. The main exploit logic is implemented in 'exploit.c', which is a C program designed to be built with the Android NDK (as described in the provided Makefile and Android.mk). The exploit works by searching for and manipulating kernel symbols in memory, specifically targeting the /dev/ptmx device to overwrite kernel function pointers and escalate privileges. Upon successful exploitation, the binary spawns a root shell (/system/bin/sh) or executes custom shellcode if provided. The repository includes build scripts for compiling and deploying the exploit to an Android device via adb. The exploit is operational and provides a working root shell on affected devices. Notable fingerprintable endpoints include the device file '/dev/ptmx' and the shell path '/system/bin/sh'.
This repository contains a proof-of-concept (POC) local privilege escalation exploit for Android systems. The main code is in 'put_user.c', which implements a technique to write up to 3 zero bytes to an arbitrary kernel memory address by abusing pipes and the ioctl system call. The exploit is intended to be used for tasks such as installing a malicious handler for '/dev/ptmx' or modifying the '/proc/sys/kernel/uevent_helper' string, both of which can be leveraged for further privilege escalation or code execution. The code is written in C and is structured as a static library (as indicated by the Android.mk build file). The exploit requires local code execution on a vulnerable Android device and does not target any specific CVE, but is generally applicable to systems with the relevant kernel bug. No network endpoints are present; the attack vector is purely local. The repository is small, with only two code files and a simple build script.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.