188 Linux Kernel CVEs in 2013

Full year · Source: NIST NVD

2012 2014

In 2013, 188 Linux kernel CVEs were published, sourced from the NIST National Vulnerability Database. Of these, 1 was rated Critical, 19 High severity , and 3 were confirmed as actively exploited in the wild (CISA KEV) . Compared to 2012's 114 CVEs, 2013 represented an increase of 65% year-on-year. March was the most active month, with 40 CVEs published.

188
Total CVEs
1
Critical
19
High
122
Medium
46
Low
3
KEV Exploited

Monthly CVE Breakdown — 2013

CVEs published per month with severity breakdown

Monthly highlight

March (40) was the most active month in 2013. Together the top months account for a significant share of 2013's 188 total CVEs. October (3) had the lowest volume.

Critical
High
Medium
Low
Source: NIST NVD API.

Severity Distribution — 2013

Breakdown across 188 CVEs

Critical 1%
High 10%
Medium 65%
Low 24%
Severity breakdown

65% Medium · 10% High · 1% Critical.

Percentages rounded to nearest integer.

Monthly Counts — 2013

CVE counts by month and severity

Monthly highlight

March was the most active month with 40 CVEs — 21% of 2013's total. October (3) had the lowest volume.

Month Total Critical High Medium Low Share of year
January 5 0 0 4 1
3%
February 24 0 1 19 4
13%
March 40 0 1 15 24
21%
April 26 0 3 21 2
14%
May 4 0 2 1 1
2%
June 18 1 3 8 6
10%
July 12 0 2 7 3
6%
August 4 0 1 3 0
2%
September 17 0 1 14 2
9%
October 3 0 0 3 0
2%
November 23 0 4 19 0
12%
December 12 0 1 8 3
6%
Total 188 1 19 122 46
Click any month to view all CVEs published that month.

Actively exploited CVEs — 2013

3 CVEs confirmed in CISA KEV catalog

CVE ID Severity CVSS Published Description
CVE-2013-6282 High KEV 8.8 2013-11-20 The (1) get_user and (2) put_user API functions in the Linux kernel before 3.5.5 on the v6k and v7 …
CVE-2013-2094 High KEV 8.4 2013-05-14 The perf_swevent_init function in kernel/events/core.c in the Linux kernel before 3.8.9 uses an inc…
CVE-2013-2596 High KEV 7.8 2013-04-13 Integer overflow in the fb_mmap function in drivers/video/fbmem.c in the Linux kernel before 3.8.9,…
KEV data sourced from CISA Known Exploited Vulnerabilities catalog.

All CVEs — 2013

188 CVEs

All (188) Critical (1) High (19) Medium (122) Low (46)
CVE ID Package Severity CVSS Published Description
CVE-2011-1180 linux Critical 9.8 2013-06-08 Multiple stack-based buffer overflows in the iriap_getvaluebyclass_indication function in net/irda/iriap.c in the Linux…
CVE-2013-6282 linux High KEV 8.8 2013-11-20 The (1) get_user and (2) put_user API functions in the Linux kernel before 3.5.5 on the v6k and v7 ARM platforms do not…
CVE-2013-2094 linux High KEV 8.4 2013-05-14 The perf_swevent_init function in kernel/events/core.c in the Linux kernel before 3.8.9 uses an incorrect integer data …
CVE-2013-2850 linux High 7.9 2013-06-07 Heap-based buffer overflow in the iscsi_add_notunderstood_response function in drivers/target/iscsi/iscsi_target_parame…
CVE-2013-4247 linux High 7.8 2013-08-25 Off-by-one error in the build_unc_path_to_root function in fs/cifs/connect.c in the Linux kernel before 3.9.6 allows re…
CVE-2013-1943 linux High 7.8 2013-07-16 The KVM subsystem in the Linux kernel before 3.0 does not check whether kernel addresses are specified during allocatio…
CVE-2013-1059 linux High 7.8 2013-07-08 net/ceph/auth_none.c in the Linux kernel through 3.10 allows remote attackers to cause a denial of service (NULL pointe…
CVE-2013-2017 linux High 7.8 2013-05-03 The veth (aka virtual Ethernet) driver in the Linux kernel before 2.6.34 does not properly manage skbs during congestio…
CVE-2013-2596 linux High KEV 7.8 2013-04-13 Integer overflow in the fb_mmap function in drivers/video/fbmem.c in the Linux kernel before 3.8.9, as used in a certai…
CVE-2011-4087 linux High 7.5 2013-06-08 The br_parse_ip_options function in net/bridge/br_netfilter.c in the Linux kernel before 2.6.39 does not properly initi…

2013 Linux Kernel CVE Highlights

  • Volume without critical severity

    Despite high CVE volume, 2013 produced only 1 Critical-rated vulnerability. 65% of 2013 CVEs are Medium severity. This means the surge in raw numbers does not represent a proportional surge in high-severity risk.

  • Monthly variation

    CVE publication in 2013 was uneven across months. March was the most active with 40 CVEs. October (3) had the lowest volume. Monthly spikes typically correspond to coordinated batches of backfilled CVEs being processed at once.

Frequently Asked Questions

How many Linux kernel CVEs were published in 2013?

188 Linux kernel CVEs were published in 2013, sourced from the NIST National Vulnerability Database. 1 was rated Critical, 19 High severity , and 3 were confirmed as actively exploited via CISA KEV .

Which month had the most Linux kernel CVEs in 2013?

March 2013 had the most Linux kernel CVEs of any month in 2013, with 40 published — 21% of all 2013 CVEs. View March 2013 CVEs →

How many Linux kernel CVEs in 2013 are actively exploited?

3 Linux kernel CVEs from 2013 are listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, confirming active exploitation in the wild. The actively exploited rate for 2013 is 16 per 1,000 CVEs. View actively exploited CVEs from 2013 →

Why were there so many Linux kernel CVEs in 2013?

The volume of Linux kernel CVEs in 2013 reflects the kernel project's expanded use of its own CVE Numbering Authority (CNA), which began systematically publishing CVEs for a broader range of subsystem-level bugs — including many previously unreported or patched without a CVE assignment. This explains why volume surged while critical severity counts remained very low.

How does 2013 compare to previous years for Linux kernel CVEs?

2013 had 188 CVEs — increase of 65% compared to 2012's 114 . View the full year-by-year breakdown →

2012 statistics All-time stats 2014 statistics