CVE-2013-4511

medium
Published 2013-11-12 · Modified 2026-04-29
CVSS v3
CVSS v2
6.9
VIR risk
6.9

Description

Multiple integer overflows in Alchemy LCD frame-buffer drivers in the Linux kernel before 3.12 allow local users to create a read-write memory mapping for the entirety of kernel memory, and consequently gain privileges, via crafted mmap operations, related to the (1) au1100fb_fb_mmap function in drivers/video/au1100fb.c and the (2) au1200fb_fb_mmap function in drivers/video/au1200fb.c.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2013-4511

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — https://www.kernel.org/pub/linux/kernel/v3.x/patch-3.12.bz2

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — https://github.com/torvalds/linux/commit/7314e613d5ff9f0934f7a0f74ed7973b903315d1

OS impact

OSVersionStatusFixed in
debian debianbookwormfixed3.11.8-1
debian debianbullseyefixed3.11.8-1
debian debianforkyfixed3.11.8-1
debian debiansidfixed3.11.8-1
debian debiantrixiefixed3.11.8-1
linux linux-kernelaffected3.2.53

References

CWEs

CWE-189

Verify integrity in audit chain (admin only). AS-IS.