Loading
The (1) get_user and (2) put_user API functions in the Linux kernel before 3.5.5 on the v6k and v7 ARM platforms do not validate certain addresses, which allows attackers to read or modify the contents of arbitrary kernel memory locations via a crafted application, as exploited in the wild against Android devices in October and November 2013.
Use CWE-20, Linux vendor hub and Linux Kernel product page to widen CVE-2013-6282 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2026-6920, CVE-2026-6919 and CVE-2026-6318 for nearby disclosures in the same product family.