First published: Mon Oct 20 2008(Updated: )
The i915 driver in (1) drivers/char/drm/i915_dma.c in the Linux kernel 2.6.24 on Debian GNU/Linux and (2) sys/dev/pci/drm/i915_drv.c in OpenBSD does not restrict the DRM_I915_HWS_ADDR ioctl to the Direct Rendering Manager (DRM) master, which allows local users to cause a denial of service (memory corruption) via a crafted ioctl call, related to absence of the DRM_MASTER and DRM_ROOT_ONLY flags in the ioctl's configuration.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Linux Kernel | =2.6.24 | |
Debian | ||
OpenBSD |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-3831 has a medium severity rating due to its potential for causing denial of service.
To fix CVE-2008-3831, you should update to the latest version of the Linux kernel that has resolved this vulnerability.
CVE-2008-3831 primarily affects the Linux kernel version 2.6.24 on Debian GNU/Linux.
No, CVE-2008-3831 requires local user access to exploit the vulnerability.
Exploiting CVE-2008-3831 can lead to a denial of service condition on affected systems.