Skip to main content

CVE-2013-2597

8.4
HIGHCVSS v3.1 Base Score
6.10%
LOW RiskEPSS (91st percentile)
KEV
NVD-CWE-Other

Stack-based buffer overflow in the acdb_ioctl function in audio_acdb.c in the acdb audio driver for the Linux kernel 2.6.x and 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, allows attackers to gain privileges via an application that leverages /dev/msm_acdb access and provides a large size value in an ioctl argument.

Published: 8/31/2014
Modified: 4/22/2026
Back to CVE Lookup

ACTIVELY EXPLOITED IN THE WILD

This vulnerability is listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.

Vulnerability Name:

Code Aurora ACDB Audio Driver Stack-based Buffer Overflow Vulnerability

Vendor / Product:

Code Aurora ACDB Audio Driver

Required Action:

Apply updates per vendor instructions.

Due Date: 10/6/2022(OVERDUE)
Added to KEV:

9/15/2022

Notes:

https://web.archive.org/web/20161226013354/https:/www.codeaurora.org/news/security-advisories/stack-based-buffer-overflow-acdb-audio-driver-cve-2013-2597; https://nvd.nist.gov/vuln/detail/CVE-2013-2597

Vulnerability Summary

CVSS v3 Score

8.4HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CVSS v2 Score

7.2

AV:L/AC:L/Au:N/C:C/I:C/A:C

EPSS Score (Exploitation Probability)

6.10%LOW Exploitation Risk
91st percentile

This vulnerability has a 6.10% probability of being exploited in the next 30 days, ranking higher than 91% of all scored CVEs.

CWE Classification

NVD-CWE-Other

Related Vulnerabilities