CVE-2013-2094
The perf_swevent_init function in kernel/events/core.c in the Linux kernel before 3.8.9 uses an incorrect integer data type, which allows local users to gain privileges via a crafted perf_event_open system call.
CVSS
- Version: 3.1
- Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Base score: 8.4
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 48%
- Percentile among all scored CVEs: 99
- Score date: 10/9/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
CISA KEV — actively exploited
- Added to catalog: 9/15/2022
- Remediation due date: 10/6/2022
- Known ransomware use: Unknown
💥 Public exploits
Exploit code or detection templates are publicly available. This is not the same as confirmed active exploitation (KEV), but it raises the risk: patch with priority.
- Published on Exploit-DB · Linux Kernel 3.2.0-23/3.5.0-23 (Ubuntu 12.04/12.04.1/12.04.2 x64) - 'perf_swevent_init' Local Privilege Escalation (3) (5/31/2014)
- Published on Exploit-DB · Linux Kernel < 3.8.9 (x86-64) - 'perf_swevent_init' Local Privilege Escalation (2) (6/11/2013)
- Published on Exploit-DB · Linux Kernel 2.6.32 < 3.x (CentOS 5/6) - 'PERF_EVENTS' Local Privilege Escalation (1) (5/14/2013)
- Proof of concept on GitHub (unverified) · List of proofs of concept on GitHub
⚠️ GitHub proofs of concept are not verified: some are fake or contain malware. Never run them outside an isolated lab.
🎯 ATT&CK techniques
How this vulnerability is exploited and what the attacker gains, in MITRE ATT&CK terms.
- Exploitation
T1068Exploitation for Privilege Escalationprivilege escalation95 % - Primary impact
T1059.004Unix Shellexecution75 % - Secondary impact
T1548Abuse Elevation Control Mechanismprivilege escalation80 %
Vulnerabilidad en kernel Linux explorada localmente sin privilegios (AV:L/PR:N) para escalar privilegios mediante perf_event_open, confirmada en KEV con uso activo en ransomware. Permite ejecución con permisos elevados.
Inferred by our analysis agent from the official description, CVSS vector and CWE, and checked by a supervisor. May contain errors.
🛡️ ATT&CK mitigations that cover these techniques
Affected technologies (1)
CWEs
- CWE-189
References
- http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=8176cced706b5e5d15887584150764894e94e02f
- http://lists.centos.org/pipermail/centos-announce/2013-May/019729.html
- http://lists.centos.org/pipermail/centos-announce/2013-May/019733.html
- http://lists.opensuse.org/opensuse-security-announce/2013-05/msg00008.html
- http://lists.opensuse.org/opensuse-security-announce/2013-05/msg00018.html
- http://lists.opensuse.org/opensuse-security-announce/2013-06/msg00005.html
- http://lists.opensuse.org/opensuse-security-announce/2013-06/msg00009.html
- http://lists.opensuse.org/opensuse-security-announce/2013-06/msg00017.html
- http://lkml.indiana.edu/hypermail/linux/kernel/1304.1/03652.html
- http://lkml.indiana.edu/hypermail/linux/kernel/1304.1/03976.html
- http://lkml.indiana.edu/hypermail/linux/kernel/1304.1/04302.html
- http://news.ycombinator.com/item?id=5703758
- http://packetstormsecurity.com/files/121616/semtex.c
- http://rhn.redhat.com/errata/RHSA-2013-0830.html
- http://twitter.com/djrbliss/statuses/334301992648331267
- http://www.exploit-db.com/exploits/33589
- http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.8.9
- http://www.mandriva.com/security/advisories?name=MDVSA-2013:176
- http://www.openwall.com/lists/oss-security/2013/05/14/6
- http://www.osvdb.org/93361
- http://www.reddit.com/r/netsec/comments/1eb9iw
- http://www.ubuntu.com/usn/USN-1825-1
- http://www.ubuntu.com/usn/USN-1826-1
- http://www.ubuntu.com/usn/USN-1827-1
- http://www.ubuntu.com/usn/USN-1828-1
- http://www.ubuntu.com/usn/USN-1836-1
- http://www.ubuntu.com/usn/USN-1838-1
- https://bugzilla.redhat.com/show_bug.cgi?id=962792
- https://github.com/torvalds/linux/commit/8176cced706b5e5d15887584150764894e94e02f
- http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=8176cced706b5e5d15887584150764894e94e02f
- http://lists.centos.org/pipermail/centos-announce/2013-May/019729.html
- http://lists.centos.org/pipermail/centos-announce/2013-May/019733.html
- http://lists.opensuse.org/opensuse-security-announce/2013-05/msg00008.html
- http://lists.opensuse.org/opensuse-security-announce/2013-05/msg00018.html
- http://lists.opensuse.org/opensuse-security-announce/2013-06/msg00005.html
- http://lists.opensuse.org/opensuse-security-announce/2013-06/msg00009.html
- http://lists.opensuse.org/opensuse-security-announce/2013-06/msg00017.html
- http://lkml.indiana.edu/hypermail/linux/kernel/1304.1/03652.html
- http://lkml.indiana.edu/hypermail/linux/kernel/1304.1/03976.html
- http://lkml.indiana.edu/hypermail/linux/kernel/1304.1/04302.html
- http://news.ycombinator.com/item?id=5703758
- http://packetstormsecurity.com/files/121616/semtex.c
- http://rhn.redhat.com/errata/RHSA-2013-0830.html
- http://twitter.com/djrbliss/statuses/334301992648331267
- http://www.exploit-db.com/exploits/33589
- http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.8.9
- http://www.mandriva.com/security/advisories?name=MDVSA-2013:176
- http://www.openwall.com/lists/oss-security/2013/05/14/6
- http://www.osvdb.org/93361
- http://www.reddit.com/r/netsec/comments/1eb9iw
- http://www.ubuntu.com/usn/USN-1825-1
- http://www.ubuntu.com/usn/USN-1826-1
- http://www.ubuntu.com/usn/USN-1827-1
- http://www.ubuntu.com/usn/USN-1828-1
- http://www.ubuntu.com/usn/USN-1836-1
- http://www.ubuntu.com/usn/USN-1838-1
- https://bugzilla.redhat.com/show_bug.cgi?id=962792
- https://github.com/torvalds/linux/commit/8176cced706b5e5d15887584150764894e94e02f
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2013-2094
Raw JSON (NVD)
Show
{
"id": "CVE-2013-2094",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2013-2094",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "active"
},
{
"automatable": "no"
},
{
"technicalImpact": "total"
}
],
"version": "2.0.3",
"timestamp": "2025-05-01T03:55:11.896804Z"
}
}
],
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 7.2,
"accessVector": "LOCAL",
"vectorString": "AV:L/AC:L/Au:N/C:C/I:C/A:C",
"authentication": "NONE",
"integrityImpact": "COMPLETE",
"accessComplexity": "LOW",
"availabilityImpact": "COMPLETE",
"confidentialityImpact": "COMPLETE"
},
"acInsufInfo": false,
"impactScore": 10,
"baseSeverity": "HIGH",
"obtainAllPrivilege": false,
"exploitabilityScore": 3.9,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 8.4,
"attackVector": "LOCAL",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 2.5
}
]
},
"affected": [
{
"source": "secalert@redhat.com",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2013-05-14T20:55:01.527",
"references": [
{
"url": "http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=8176cced706b5e5d15887584150764894e94e02f",
"tags": [
"Not Applicable"
],
"source": "secalert@redhat.com"
},
{
"url": "http://lists.centos.org/pipermail/centos-announce/2013-May/019729.html",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"source": "secalert@redhat.com"
},
{
"url": "http://lists.centos.org/pipermail/centos-announce/2013-May/019733.html",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"source": "secalert@redhat.com"
},
{
"url": "http://lists.opensuse.org/opensuse-security-announce/2013-05/msg00008.html",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"source": "secalert@redhat.com"
},
{
"url": "http://lists.opensuse.org/opensuse-security-announce/2013-05/msg00018.html",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"source": "secalert@redhat.com"
},
{
"url": "http://lists.opensuse.org/opensuse-security-announce/2013-06/msg00005.html",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"source": "secalert@redhat.com"
},
{
"url": "http://lists.opensuse.org/opensuse-security-announce/2013-06/msg00009.html",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"source": "secalert@redhat.com"
},
{
"url": "http://lists.opensuse.org/opensuse-security-announce/2013-06/msg00017.html",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"source": "secalert@redhat.com"
},
{
"url": "http://lkml.indiana.edu/hypermail/linux/kernel/1304.1/03652.html",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"source": "secalert@redhat.com"
},
{
"url": "http://lkml.indiana.edu/hypermail/linux/kernel/1304.1/03976.html",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"source": "secalert@redhat.com"
},
{
"url": "http://lkml.indiana.edu/hypermail/linux/kernel/1304.1/04302.html",
"tags": [
"Third Party Advisory"
],
"source": "secalert@redhat.com"
},
{
"url": "http://news.ycombinator.com/item?id=5703758",
"tags": [
"Third Party Advisory"
],
"source": "secalert@redhat.com"
},
{
"url": "http://packetstormsecurity.com/files/121616/semtex.c",
"tags": [
"Exploit",
"Third Party Advisory",
"VDB Entry"
],
"source": "secalert@redhat.com"
},
{
"url": "http://rhn.redhat.com/errata/RHSA-2013-0830.html",
"tags": [
"Third Party Advisory"
],
"source": "secalert@redhat.com"
},
{
"url": "http://twitter.com/djrbliss/statuses/334301992648331267",
"tags": [
"Patch"
],
"source": "secalert@redhat.com"
},
{
"url": "http://www.exploit-db.com/exploits/33589",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"source": "secalert@redhat.com"
},
{
"url": "http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.8.9",
"tags": [
"Not Applicable"
],
"source": "secalert@redhat.com"
},
{
"url": "http://www.mandriva.com/security/advisories?name=MDVSA-2013:176",
"tags": [
"Mailing List",
"Third Party Advisory"
],
"source": "secalert@redhat.com"
},
{
"url": "http://www.openwall.com/lists/oss-security/2013/05/14/6",
"tags": [
"Mailing List",
"Third Party Advisory"
],
"source": "secalert@redhat.com"
},
{
"url": "http://www.osvdb.org/93361",
"tags": [
"Broken Link"
],
"source": "secalert@redhat.com"
},
{
"url": "http://www.reddit.com/r/netsec/comments/1eb9iw",
"tags": [
"Third Party Advisory"
],
"source": "secalert@redhat.com"
},
{
"url": "http://www.ubuntu.com/usn/USN-1825-1",
"tags": [
"Third Party Advisory"
],
"source": "secalert@redhat.com"
},
{
"url": "http://www.ubuntu.com/usn/USN-1826-1",
"tags": [
"Third Party Advisory"
],
"source": "secalert@redhat.com"
},
{
"url": "http://www.ubuntu.com/usn/USN-1827-1",
"tags": [
"Third Party Advisory"
],
"source": "secalert@redhat.com"
},
{
"url": "http://www.ubuntu.com/usn/USN-1828-1",
"tags": [
"Third Party Advisory"
],
"source": "secalert@redhat.com"
},
{
"url": "http://www.ubuntu.com/usn/USN-1836-1",
"tags": [
"Third Party Advisory"
],
"source": "secalert@redhat.com"
},
{
"url": "http://www.ubuntu.com/usn/USN-1838-1",
"tags": [
"Third Party Advisory"
],
"source": "secalert@redhat.com"
},
{
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=962792",
"tags": [
"Issue Tracking"
],
"source": "secalert@redhat.com"
},
{
"url": "https://github.com/torvalds/linux/commit/8176cced706b5e5d15887584150764894e94e02f",
"tags": [
"Third Party Advisory"
],
"source": "secalert@redhat.com"
},
{
"url": "http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=8176cced706b5e5d15887584150764894e94e02f",
"tags": [
"Not Applicable"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://lists.centos.org/pipermail/centos-announce/2013-May/019729.html",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://lists.centos.org/pipermail/centos-announce/2013-May/019733.html",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://lists.opensuse.org/opensuse-security-announce/2013-05/msg00008.html",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://lists.opensuse.org/opensuse-security-announce/2013-05/msg00018.html",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://lists.opensuse.org/opensuse-security-announce/2013-06/msg00005.html",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://lists.opensuse.org/opensuse-security-announce/2013-06/msg00009.html",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://lists.opensuse.org/opensuse-security-announce/2013-06/msg00017.html",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://lkml.indiana.edu/hypermail/linux/kernel/1304.1/03652.html",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://lkml.indiana.edu/hypermail/linux/kernel/1304.1/03976.html",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://lkml.indiana.edu/hypermail/linux/kernel/1304.1/04302.html",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://news.ycombinator.com/item?id=5703758",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://packetstormsecurity.com/files/121616/semtex.c",
"tags": [
"Exploit",
"Third Party Advisory",
"VDB Entry"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://rhn.redhat.com/errata/RHSA-2013-0830.html",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://twitter.com/djrbliss/statuses/334301992648331267",
"tags": [
"Patch"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.exploit-db.com/exploits/33589",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.8.9",
"tags": [
"Not Applicable"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.mandriva.com/security/advisories?name=MDVSA-2013:176",
"tags": [
"Mailing List",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.openwall.com/lists/oss-security/2013/05/14/6",
"tags": [
"Mailing List",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.osvdb.org/93361",
"tags": [
"Broken Link"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.reddit.com/r/netsec/comments/1eb9iw",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.ubuntu.com/usn/USN-1825-1",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.ubuntu.com/usn/USN-1826-1",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.ubuntu.com/usn/USN-1827-1",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.ubuntu.com/usn/USN-1828-1",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.ubuntu.com/usn/USN-1836-1",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.ubuntu.com/usn/USN-1838-1",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=962792",
"tags": [
"Issue Tracking"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://github.com/torvalds/linux/commit/8176cced706b5e5d15887584150764894e94e02f",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2013-2094",
"tags": [
"US Government Resource"
],
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0"
}
],
"vulnStatus": "Analyzed",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-189"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "The perf_swevent_init function in kernel/events/core.c in the Linux kernel before 3.8.9 uses an incorrect integer data type, which allows local users to gain privileges via a crafted perf_event_open system call."
},
{
"lang": "es",
"value": "La función perf_swevent_init en kernel/events/core.c en el Kernel de Linux anterior a v3.8.9 usa un tipo de datos entero incorrecto, lo que permite a usuarios locales ganar privilegios mediante una llamada al sistema perf_event_open especialmente diseñada."
}
],
"lastModified": "2026-06-16T23:52:44.150",
"cisaActionDue": "2022-10-06",
"cisaExploitAdd": "2022-09-15",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "4A84D169-58BB-49ED-A9F4-776E182C22D8",
"versionEndExcluding": "3.0.75"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "88DA168C-393B-4853-8034-6E9099CC9623",
"versionEndExcluding": "3.2.45",
"versionStartIncluding": "3.1"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "8FECB4AF-F9DF-44E3-BD62-741D5D129053",
"versionEndExcluding": "3.4.42",
"versionStartIncluding": "3.3"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "7E3C2571-AFE5-4ED0-810D-232092DD0220",
"versionEndExcluding": "3.8.9",
"versionStartIncluding": "3.5"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "secalert@redhat.com",
"cisaRequiredAction": "Apply updates per vendor instructions.",
"cisaVulnerabilityName": "Linux Kernel Privilege Escalation Vulnerability"
}