CVE-2013-7445

high
Published 2015-10-16 · Modified 2026-05-06
CVSS v3
CVSS v2
7.8
VIR risk
7.8

Description

The Direct Rendering Manager (DRM) subsystem in the Linux kernel through 4.x mishandles requests for Graphics Execution Manager (GEM) objects, which allows context-dependent attackers to cause a denial of service (memory consumption) via an application that processes graphics data, as demonstrated by JavaScript code that creates many CANVAS elements for rendering by Chrome or Firefox.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2013-7445

vendor Authored 2026-05-27

Vendor advisory: suse — https://www.suse.com/security/cve/CVE-2013-7445.html

OS impact

OSVersionStatusFixed in
suse slesaffected
debian debianbookwormaffected
debian debianbullseyeaffected
debian debianforkyaffected
debian debiansidaffected
debian debiantrixieaffected
linux linux-kernelaffected
linux linux-kernel4.0.1affected
linux linux-kernel4.0.2affected
linux linux-kernel4.0.3affected
linux linux-kernel4.0.4affected
linux linux-kernel4.0.5affected
linux linux-kernel4.0.6affected
linux linux-kernel4.0.7affected
linux linux-kernel4.0.8affected
linux linux-kernel4.0.9affected
linux linux-kernel4.1.1affected
linux linux-kernel4.1.2affected
linux linux-kernel4.1.3affected
linux linux-kernel4.1.4affected
linux linux-kernel4.1.5affected
linux linux-kernel4.1.6affected
linux linux-kernel4.1.7affected
linux linux-kernel4.1.8affected
linux linux-kernel4.1.9affected
linux linux-kernel4.1.10affected
linux linux-kernel4.2.1affected
linux linux-kernel4.2.2affected
linux linux-kernel4.2.3affected

References

CWEs

CWE-399

Verify integrity in audit chain (admin only). AS-IS.