First published: Tue Jan 10 2012(Updated: )
Integer overflow in the drm_mode_dirtyfb_ioctl function in drivers/gpu/drm/drm_crtc.c in the Direct Rendering Manager (DRM) subsystem in the Linux kernel before 3.1.5 allows local users to gain privileges or cause a denial of service (memory corruption) via a crafted ioctl call.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
debian/linux-2.6 | ||
Linux Kernel | <3.0.13 | |
Linux Kernel | >=3.1<3.1.5 | |
Ubuntu Linux | =10.04 | |
Ubuntu | =10.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-0044 has a medium severity rating, as it can lead to local privilege escalation or denial of service.
To fix CVE-2012-0044, update the Linux kernel to version 3.1.5 or later.
CVE-2012-0044 affects Linux kernel versions prior to 3.1.5, including Debian and Ubuntu 10.04.
CVE-2012-0044 requires local access to exploit, so it cannot be exploited remotely.
CVE-2012-0044 involves the Direct Rendering Manager (DRM) subsystem in the Linux kernel.