Vulnerability Intelligence Report
Code Aurora ACDB Audio Driver Stack-based Buffer Overflow Vulnerability
CVE-2013-2597
Stack-based buffer overflow in the acdb_ioctl function in audio_acdb.c in the acdb audio driver for the Linux kernel 2.6.x and 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, allows attackers to gain privileges via an application that leverages /dev/msm_acdb access and provides a large size value in an ioctl argument.
CISA KEV
SSVC: Active Exploitation
CVSS Base Score
8.4
HIGH
Exploitability:2.6
Impact Score:5.9
EPSS Probability:1.52%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-121 ↗CWE-121 Stack-based Buffer Overflow
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| codeaurora | android-msm | 2.6.29, 3.2.54, 3.2.55, 3.2.56, 3.2.57, 3.2.58, 3.2.59, 3.2.60, 3.2.61, 3.2.62, 3.4.72, 3.4.73, 3.4.74, 3.4.75, 3.4.76, 3.4.77, 3.4.78, 3.4.79, 3.4.80, 3.4.81, 3.4.82, 3.4.83, 3.4.84, 3.4.85, 3.4.86, 3.4.87, 3.4.88, 3.4.89, 3.4.90, 3.4.91, 3.4.92, 3.4.93, 3.4.94, 3.4.95, 3.4.96, 3.4.97, 3.4.98, 3.4.99, 3.4.100, 3.4.101, 3.4.102, 3.4.103, 3.10, 3.10.22, 3.10.23, 3.10.24, 3.10.25, 3.10.26, 3.10.27, 3.10.28, 3.10.29, 3.10.30, 3.10.31, 3.10.32, 3.10.33, 3.10.35, 3.10.36, 3.10.37, 3.10.38, 3.10.39, 3.10.40, 3.10.41, 3.10.42, 3.10.43, 3.10.44, 3.10.45, 3.10.46, 3.10.47, 3.10.48, 3.10.49, 3.10.50, 3.10.51, 3.10.52, 3.10.53, 3.12.3, 3.12.4, 3.12.5, 3.12.6, 3.12.7, 3.12.8, 3.12.9, 3.12.10, 3.12.11, 3.12.12, 3.12.13, 3.12.14, 3.12.15, 3.12.16, 3.12.17, 3.12.18, 3.12.19, 3.12.20, 3.12.21, 3.12.22, 3.12.23, 3.12.24, 3.12.25, 3.12.26, 3.13, 3.13.1, 3.13.2, 3.13.3, 3.13.4, 3.13.5, 3.13.6, 3.13.7, 3.13.8, 3.13.9, 3.13.10, 3.13.11, 3.14, 3.14.1, 3.14.2, 3.14.3, 3.14.4, 3.14.5, 3.14.6, 3.14.7, 3.14.8, 3.14.9, 3.14.10, 3.14.11, 3.14.12, 3.14.13, 3.14.14, 3.14.15, 3.14.16, 3.15, 3.15.1, 3.15.2, 3.15.3, 3.15.4, 3.15.5, 3.15.6, 3.15.7, 3.15.8, 3.15.9, 3.15.10, 3.16, 3.16.1, 3.17 |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | MITRE Corporation · N/A · USA |
| Reserved | 2013-03-15T00:00:00 |
| Published | 2014-08-31T10:00:00 |
| Patch Date | 2013-06-21 |
| Last Updated | 2025-10-22T00:05:36 |
Community Chatter & Buzz