← Back to CVE List
Vulnerability Intelligence Report
Code Aurora ACDB Audio Driver Stack-based Buffer Overflow Vulnerability

CVE-2013-2597

Stack-based buffer overflow in the acdb_ioctl function in audio_acdb.c in the acdb audio driver for the Linux kernel 2.6.x and 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, allows attackers to gain privileges via an application that leverages /dev/msm_acdb access and provides a large size value in an ioctl argument.

CISA KEV SSVC: Active Exploitation
CVSS Base Score
8.4
HIGH
Exploitability:2.6
Impact Score:5.9
EPSS Probability:1.52%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—

Weaknesses (CWE)

CWE-121 ↗CWE-121 Stack-based Buffer Overflow

Affected Products & Versions

Vendor Product Affected Versions
codeaurora android-msm 2.6.29, 3.2.54, 3.2.55, 3.2.56, 3.2.57, 3.2.58, 3.2.59, 3.2.60, 3.2.61, 3.2.62, 3.4.72, 3.4.73, 3.4.74, 3.4.75, 3.4.76, 3.4.77, 3.4.78, 3.4.79, 3.4.80, 3.4.81, 3.4.82, 3.4.83, 3.4.84, 3.4.85, 3.4.86, 3.4.87, 3.4.88, 3.4.89, 3.4.90, 3.4.91, 3.4.92, 3.4.93, 3.4.94, 3.4.95, 3.4.96, 3.4.97, 3.4.98, 3.4.99, 3.4.100, 3.4.101, 3.4.102, 3.4.103, 3.10, 3.10.22, 3.10.23, 3.10.24, 3.10.25, 3.10.26, 3.10.27, 3.10.28, 3.10.29, 3.10.30, 3.10.31, 3.10.32, 3.10.33, 3.10.35, 3.10.36, 3.10.37, 3.10.38, 3.10.39, 3.10.40, 3.10.41, 3.10.42, 3.10.43, 3.10.44, 3.10.45, 3.10.46, 3.10.47, 3.10.48, 3.10.49, 3.10.50, 3.10.51, 3.10.52, 3.10.53, 3.12.3, 3.12.4, 3.12.5, 3.12.6, 3.12.7, 3.12.8, 3.12.9, 3.12.10, 3.12.11, 3.12.12, 3.12.13, 3.12.14, 3.12.15, 3.12.16, 3.12.17, 3.12.18, 3.12.19, 3.12.20, 3.12.21, 3.12.22, 3.12.23, 3.12.24, 3.12.25, 3.12.26, 3.13, 3.13.1, 3.13.2, 3.13.3, 3.13.4, 3.13.5, 3.13.6, 3.13.7, 3.13.8, 3.13.9, 3.13.10, 3.13.11, 3.14, 3.14.1, 3.14.2, 3.14.3, 3.14.4, 3.14.5, 3.14.6, 3.14.7, 3.14.8, 3.14.9, 3.14.10, 3.14.11, 3.14.12, 3.14.13, 3.14.14, 3.14.15, 3.14.16, 3.15, 3.15.1, 3.15.2, 3.15.3, 3.15.4, 3.15.5, 3.15.6, 3.15.7, 3.15.8, 3.15.9, 3.15.10, 3.16, 3.16.1, 3.17

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

CISA KEV
ACTIVE IN CATALOG
EPSS Score
1.516%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityMITRE Corporation · N/A · USA
Reserved2013-03-15T00:00:00
Published2014-08-31T10:00:00
Patch Date2013-06-21
Last Updated2025-10-22T00:05:36

LINK COPIED TO CLIPBOARD