CVE-2010-3448: Medium severity Linux Linux kernel vulnerability
drivers/platform/x86/thinkpadacpi.c in the Linux kernel before 2.6.34 on ThinkPad devices, when the X.Org X server is used, does not properly restrict access to the video output control state, which allows local users to cause a denial of service (system hang) via a (1) read or (2) write operation.
Other sources
Given the right combination of ThinkPad and X.org, just reading the video output control state is enough to hard-crash X.org.
Until the day I somehow find out a model or BIOS cut date to not provide this feature to ThinkPads that can do video switching through X RandR, change permissions so that only processes with CAPSYSADMIN can access any sort of video output control state.
This bug could be considered a local DoS I suppose, as it allows any non-privledged local user to cause some versions of X.org to hard-crash some ThinkPads.
Reported-by: Jidanni <jidanni> Signed-off-by: Henrique de Moraes Holschuh <hmh.br> Cc: stable
Upstream commit: http://git.kernel.org/linus/b525c06cdbd8a3963f0173ccd23f9147d4c384b5
— Red Hat
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2010-3448?
CVE-2010-3448 is classified as a medium severity vulnerability due to its potential to cause a denial of service on affected ThinkPad devices.
How do I fix CVE-2010-3448?
To mitigate CVE-2010-3448, upgrade to Linux kernel version 2.6.34 or later.
Which devices are affected by CVE-2010-3448?
CVE-2010-3448 primarily affects ThinkPad devices running Linux kernel versions before 2.6.34.
What type of attack does CVE-2010-3448 enable?
CVE-2010-3448 allows local users to execute read or write operations that can lead to a system hang.
Is CVE-2010-3448 specific to any particular Linux distribution?
While CVE-2010-3448 affects the Linux kernel, it has been reported in distributions like Debian and Red Hat.