CVE-2010-3448: Medium severity Linux Linux kernel vulnerability

Published Nov 11, 2010
·
Updated

drivers/platform/x86/thinkpadacpi.c in the Linux kernel before 2.6.34 on ThinkPad devices, when the X.Org X server is used, does not properly restrict access to the video output control state, which allows local users to cause a denial of service (system hang) via a (1) read or (2) write operation.

Other sources

Given the right combination of ThinkPad and X.org, just reading the video output control state is enough to hard-crash X.org.

Until the day I somehow find out a model or BIOS cut date to not provide this feature to ThinkPads that can do video switching through X RandR, change permissions so that only processes with CAPSYSADMIN can access any sort of video output control state.

This bug could be considered a local DoS I suppose, as it allows any non-privledged local user to cause some versions of X.org to hard-crash some ThinkPads.

Reported-by: Jidanni <jidanni> Signed-off-by: Henrique de Moraes Holschuh <hmh.br> Cc: stable

Upstream commit: http://git.kernel.org/linus/b525c06cdbd8a3963f0173ccd23f9147d4c384b5

Red Hat

Affected Software

2 affected components
debian/linux-2.6
Linux Linux kernel<2.6.34

Event History

Nov 11, 2010
Data Sourced
via Red Hat·03:06 AM
DescriptionSeverityAffected Software
Jan 3, 2011
CVE Published
via MITRE·07:26 PM
Data Sourced
via MITRE·07:26 PM
Description
Jan 11, 2024
Data Sourced
via Launchpad·09:51 PM
Description
Sep 19, 2024
Data Sourced
via Ubuntu·10:39 PM
RemedyDescriptionSeverityAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2010-3448?

CVE-2010-3448 is classified as a medium severity vulnerability due to its potential to cause a denial of service on affected ThinkPad devices.

2

How do I fix CVE-2010-3448?

To mitigate CVE-2010-3448, upgrade to Linux kernel version 2.6.34 or later.

3

Which devices are affected by CVE-2010-3448?

CVE-2010-3448 primarily affects ThinkPad devices running Linux kernel versions before 2.6.34.

4

What type of attack does CVE-2010-3448 enable?

CVE-2010-3448 allows local users to execute read or write operations that can lead to a system hang.

5

Is CVE-2010-3448 specific to any particular Linux distribution?

While CVE-2010-3448 affects the Linux kernel, it has been reported in distributions like Debian and Red Hat.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203