CVE-2010-2803
Publication date 19 August 2010
Last updated 24 July 2024
Ubuntu priority
The drm_ioctl function in drivers/gpu/drm/drm_drv.c in the Direct Rendering Manager (DRM) subsystem in the Linux kernel before 2.6.27.53, 2.6.32.x before 2.6.32.21, 2.6.34.x before 2.6.34.6, and 2.6.35.x before 2.6.35.4 allows local users to obtain potentially sensitive information from kernel memory by requesting a large memory-allocation amount.
From the Ubuntu Security Team
Kees Cook discovered that under certain situations the ioctl subsystem for DRM did not properly sanitize its arguments. A local attacker could exploit this to read previously freed kernel memory, leading to a loss of privacy.
Status
Package | Ubuntu Release | Status |
---|---|---|
linux | ||
linux-ec2 | ||
linux-fsl-imx51 | ||
linux-mvl-dove | ||
linux-source-2.6.15 | ||
Notes
Patch details
References
Related Ubuntu Security Notices (USN)
- USN-974-1
- Linux kernel vulnerabilities
- 19 August 2010
- USN-1074-1
- Linux kernel vulnerabilities
- 25 February 2011