First published: Thu Nov 11 2010(Updated: )
drivers/platform/x86/thinkpad_acpi.c in the Linux kernel before 2.6.34 on ThinkPad devices, when the X.Org X server is used, does not properly restrict access to the video output control state, which allows local users to cause a denial of service (system hang) via a (1) read or (2) write operation.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
debian/linux-2.6 | ||
Linux kernel | <2.6.34 | |
Linux Kernel | <2.6.34 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-3448 is classified as a medium severity vulnerability due to its potential to cause a denial of service on affected ThinkPad devices.
To mitigate CVE-2010-3448, upgrade to Linux kernel version 2.6.34 or later.
CVE-2010-3448 primarily affects ThinkPad devices running Linux kernel versions before 2.6.34.
CVE-2010-3448 allows local users to execute read or write operations that can lead to a system hang.
While CVE-2010-3448 affects the Linux kernel, it has been reported in distributions like Debian and Red Hat.