CVE-2004-1056
published 2005-01-10CVE-2004-1056: Direct Rendering Manager (DRM) driver in Linux kernel 2.6 does not properly check the DMA lock, which could allow remote attackers or local users to cause a…
PriorityP419medium6.4CVSS 2.0
AVNACLAuNCNIPAP
EPSS
3.27%
87.5th percentile
Direct Rendering Manager (DRM) driver in Linux kernel 2.6 does not properly check the DMA lock, which could allow remote attackers or local users to cause a denial of service (X Server crash) and possibly modify the video output.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| ubuntu | ubuntu_linux | — | — |
CVSS provenance
nvdv2.06.4MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:P
vendor_redhat6.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-jxqr-rj44-7m7x: Direct Rendering Manager (DRM) driver in Linux kernel 2
ghsa_unreviewed·2022-04-29
CVE-2004-1056 [MEDIUM] GHSA-jxqr-rj44-7m7x: Direct Rendering Manager (DRM) driver in Linux kernel 2
Direct Rendering Manager (DRM) driver in Linux kernel 2.6 does not properly check the DMA lock, which could allow remote attackers or local users to cause a denial of service (X Server crash) and possibly modify the video output.
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2004-12-15
CVE-2004-1137 Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Linux kernel vulnerabilities
CAN-2004-0814:
Vitaly V. Bursov discovered a Denial of Service vulnerability in the "serio"
code; opening the same tty device twice and doing some particular operations on
it caused a kernel panic and/or a system lockup.
Fixing this vulnerability required a change in the Application Binary
Interface (ABI) of the kernel. This means that third party user installed
modules might not work any more with the new kernel, so this fixed kernel got
a new ABI version number. You have to recompile and reinstall all third party
modules.
CAN-2004-1016:
Paul Starzetz discovered a buffer overflow vulnerability in the "__scm_send"
function which handles the sending of UDP network packets. A wrong validity
check of the cmsghdr s
Red Hat
security flaw
vendor_redhat·2004-12-14·CVSS 6.4
CVE-2004-1056 [MEDIUM] security flaw
security flaw
Direct Rendering Manager (DRM) driver in Linux kernel 2.6 does not properly check the DMA lock, which could allow remote attackers or local users to cause a denial of service (X Server crash) and possibly modify the video output.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2004-1056 security flaw
bugzilla·2018-08-16·CVSS 6.4
CVE-2004-1056 [MEDIUM] CVE-2004-1056 security flaw
CVE-2004-1056 security flaw
Flaw bug created to hold information about an old flaw we knew something about. For more details see the MITRE CVE description.
Discussion:
MITRE description:
Direct Rendering Manager (DRM) driver in Linux kernel 2.6 does not properly check the DMA lock, which could allow remote attackers or local users to cause a denial of service (X Server crash) and possibly modify the video output.
Bugzilla
CVE-2004-1056 insufficient locking checks in DRM code
bugzilla·2005-01-06·CVSS 6.4
CVE-2004-1056 [MEDIUM] CVE-2004-1056 insufficient locking checks in DRM code
CVE-2004-1056 insufficient locking checks in DRM code
*** This bug has been split off bug 138534 ***
------- Original comment by Josh Bressers (Security Response Team) on 2004.11.09
15:00 -------
Stefan Dirsch reported to the freedesktop.org bugzilla an issue with
permissions within the DRM code.
See this url for more information, including a patch.
https://freedesktop.org/bugzilla/show_bug.cgi?id=1803
Bugzilla
CVE-2004-1056 insufficient locking checks in DRM code
bugzilla·2004-11-09·CVSS 6.4
CVE-2004-1056 [MEDIUM] CVE-2004-1056 insufficient locking checks in DRM code
CVE-2004-1056 insufficient locking checks in DRM code
Stefan Dirsch reported to the freedesktop.org bugzilla an issue with
permissions within the DRM code.
See this url for more information, including a patch.
https://freedesktop.org/bugzilla/show_bug.cgi?id=1803
This issue should also affect RHEL2.1
Discussion:
This issue probably also affects RHEL4.
---
DRM source is part of both the kernel and X. We build it in the
kernel. Reassigning to kernel component.
---
Peter/Tim, I'm assuming that DaveJ is too busy with RHEL4 to take on
this bug. But I don't know who else covers this area. I'm sticking
PeterM with this for now (presumably for appropriate reassignment).
Josh, the URL in your initial comment times out. Could you please
provide another pointer? Thanks in advance.
---
fre
http://secunia.com/advisories/17002http://www.redhat.com/support/errata/RHSA-2005-092.htmlhttp://www.redhat.com/support/errata/RHSA-2005-529.htmlhttp://www.redhat.com/support/errata/RHSA-2005-551.htmlhttp://www.redhat.com/support/errata/RHSA-2005-663.htmlhttp://www.vupen.com/english/advisories/2005/1878https://bugzilla.fedora.us/show_bug.cgi?id=2336https://exchange.xforce.ibmcloud.com/vulnerabilities/15972https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9795https://www.ubuntu.com/usn/usn-38-1/http://secunia.com/advisories/17002http://www.redhat.com/support/errata/RHSA-2005-092.htmlhttp://www.redhat.com/support/errata/RHSA-2005-529.htmlhttp://www.redhat.com/support/errata/RHSA-2005-551.htmlhttp://www.redhat.com/support/errata/RHSA-2005-663.htmlhttp://www.vupen.com/english/advisories/2005/1878https://bugzilla.fedora.us/show_bug.cgi?id=2336https://exchange.xforce.ibmcloud.com/vulnerabilities/15972https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9795https://www.ubuntu.com/usn/usn-38-1/
2005-01-10
Published