CVE-2013-2597
KEVmassStack Buffer Overflow in Code Aurora ACDB Audio Driver Enables Privilege Escalation
CISA: Code Aurora ACDB Audio Driver Stack-based Buffer Overflow Vulnerability
A stack-based buffer overflow (CWE-119) exists in the audio calibration database (acdb) audio driver from Code Aurora, the code incorporated into third-party products such as Qualcomm and Android. An attacker who can get crafted input to this driver can overwrite stack memory and escalate privileges to a higher-than-intended level on the device. Any device shipping the vulnerable Code Aurora ACDB audio driver — notably Qualcomm-powered Android products — is potentially affected, though the available data does not specify affected version ranges. Exploitation is confirmed in the wild: CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2022-09-15, while EPSS estimates a 1.5% probability of exploitation in the next 30 days and no public proof-of-concept is known.
What to do: Apply updated audio drivers/firmware from your chipset or device vendor as soon as available, per CISA's required action to apply updates per vendor instructions, and check Qualcomm and Android security bulletins for fixes covering CVE-2013-2597. Because this is a local privilege escalation, prioritize Qualcomm-based Android devices where untrusted apps or users can execute code, and limit installation of untrusted applications on affected devices until patched.
| Code Aurora ACDB Audio Driver | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
The Code Aurora audio calibration database (acdb) audio driver contains a stack-based buffer overflow vulnerability that allows for privilege escalation. Code Aurora is used in third-party products such as Qualcomm and Android.
- Affected
- Code Aurora ACDB Audio Driver
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- Code Aurora
- Products
- ACDB Audio Driver
- Weakness
- CWE-119