CVE-2010-2803
published 2010-09-08CVE-2010-2803: The drm_ioctl function in drivers/gpu/drm/drm_drv.c in the Direct Rendering Manager (DRM) subsystem in the Linux kernel before 2.6.27.53, 2.6.32.x before…
PriorityP46low1.9CVSS 2.0
AVLACMAuNCPINAN
EPSS
0.47%
37.3th percentile
The drm_ioctl function in drivers/gpu/drm/drm_drv.c in the Direct Rendering Manager (DRM) subsystem in the Linux kernel before 2.6.27.53, 2.6.32.x before 2.6.32.21, 2.6.34.x before 2.6.34.6, and 2.6.35.x before 2.6.35.4 allows local users to obtain potentially sensitive information from kernel memory by requesting a large memory-allocation amount.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| linux | linux_kernel | < 2.6.27.53 | 2.6.27.53 |
| linux | linux_kernel | >= 2.6.32 < 2.6.32.21 | 2.6.32.21 |
| linux | linux_kernel | >= 2.6.34 < 2.6.34.6 | 2.6.34.6 |
| linux | linux_kernel | >= 2.6.35 < 2.6.35.4 | 2.6.35.4 |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
| suse | linux_enterprise_desktop | — | — |
| suse | linux_enterprise_high_availability_extension | — | — |
| suse | linux_enterprise_real_time | — | — |
| suse | linux_enterprise_server | — | — |
CVSS provenance
nvdv2.01.9LOWAV:L/AC:M/Au:N/C:P/I:N/A:N
vendor_ubuntu7.2HIGH
vendor_redhat1.9LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2011-02-25·CVSS 4.7
CVE-2009-4895 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Multiple kernel flaws.
Al Viro discovered a race condition in the TTY driver. A local attacker
could exploit this to crash the system, leading to a denial of service.
(CVE-2009-4895)
Dan Rosenberg discovered that the MOVE_EXT ext4 ioctl did not correctly
check file permissions. A local attacker could overwrite append-only files,
leading to potential data loss. (CVE-2010-2066)
Dan Rosenberg discovered that the swapexit xfs ioctl did not correctly
check file permissions. A local attacker could exploit this to read from
write-only files, leading to a loss of privacy. (CVE-2010-2226)
Gael Delalleu, Rafal Wojtczuk, and Brad Spengler discovered that the memory
manager did not properly handle when applications grow stacks into adjacent
memory regi
Ubuntu
Linux kernel regression
vendor_ubuntu·2010-08-26·CVSS 7.2
CVE-2010-2240 [HIGH] Linux kernel regression
Title: Linux kernel regression
Summary: This update provides a fix for the Linux kernel when using Xen.
USN-974-1 fixed vulnerabilities in the Linux kernel. The fixes for
CVE-2010-2240 caused failures for Xen hosts. This update fixes the
problem.
We apologize for the inconvenience.
Original advisory details:
Gael Delalleu, Rafal Wojtczuk, and Brad Spengler discovered that the memory
manager did not properly handle when applications grow stacks into adjacent
memory regions. A local attacker could exploit this to gain control of
certain applications, potentially leading to privilege escalation, as
demonstrated in attacks against the X server. (CVE-2010-2240)
Kees Cook discovered that under certain situations the ioctl subsystem for
DRM did not properly sanitize its arguments. A local a
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2010-08-19·CVSS 7.2
CVE-2010-2240 [HIGH] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: The Linux kernel could be made to crash or run programs as root.
Gael Delalleu, Rafal Wojtczuk, and Brad Spengler discovered that the memory
manager did not properly handle when applications grow stacks into adjacent
memory regions. A local attacker could exploit this to gain control of
certain applications, potentially leading to privilege escalation, as
demonstrated in attacks against the X server. (CVE-2010-2240)
Kees Cook discovered that under certain situations the ioctl subsystem for
DRM did not properly sanitize its arguments. A local attacker could exploit
this to read previously freed kernel memory, leading to a loss of privacy.
(CVE-2010-2803)
Ben Hawkes discovered an integer overflow in the Controller Area Network
(CAN) subsystem
Red Hat
kernel: drm ioctls infoleak
vendor_redhat·2010-08-17·CVSS 1.9
CVE-2010-2803 [LOW] kernel: drm ioctls infoleak
kernel: drm ioctls infoleak
The drm_ioctl function in drivers/gpu/drm/drm_drv.c in the Direct Rendering Manager (DRM) subsystem in the Linux kernel before 2.6.27.53, 2.6.32.x before 2.6.32.21, 2.6.34.x before 2.6.34.6, and 2.6.35.x before 2.6.35.4 allows local users to obtain potentially sensitive information from kernel memory by requesting a large memory-allocation amount.
Statement: This issue did not affect the version of Linux kernel as shipped with Red Hat
Enterprise Linux 3, 4, 5 and Red Hat Enterprise MRG as they did not include
support for GPU DRM.
GHSA
GHSA-jq68-96jh-4wjh: The drm_ioctl function in drivers/gpu/drm/drm_drv
ghsa_unreviewed·2022-05-13
CVE-2010-2803 [LOW] CWE-200 GHSA-jq68-96jh-4wjh: The drm_ioctl function in drivers/gpu/drm/drm_drv
The drm_ioctl function in drivers/gpu/drm/drm_drv.c in the Direct Rendering Manager (DRM) subsystem in the Linux kernel before 2.6.27.53, 2.6.32.x before 2.6.32.21, 2.6.34.x before 2.6.34.6, and 2.6.35.x before 2.6.35.4 allows local users to obtain potentially sensitive information from kernel memory by requesting a large memory-allocation amount.
No detection rules found.
No public exploits indexed.
http://git.kernel.org/?p=linux/kernel/git/airlied/drm-2.6.git%3Ba=commit%3Bh=1b2f1489633888d4a06028315dc19d65768a1c05http://git.kernel.org/?p=linux/kernel/git/airlied/drm-2.6.git%3Ba=commit%3Bh=b9f0aee83335db1f3915f4e42a5e21b351740afdhttp://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=b9f0aee83335db1f3915f4e42a5e21b351740afdhttp://lists.opensuse.org/opensuse-security-announce/2010-09/msg00004.htmlhttp://lists.opensuse.org/opensuse-security-announce/2010-09/msg00005.htmlhttp://lists.opensuse.org/opensuse-security-announce/2010-11/msg00000.htmlhttp://lists.opensuse.org/opensuse-security-announce/2011-02/msg00000.htmlhttp://secunia.com/advisories/41512http://www.debian.org/security/2010/dsa-2094http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.27.53http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.32.21http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.34.6http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.35.4http://www.mandriva.com/security/advisories?name=MDVSA-2010:198http://www.redhat.com/support/errata/RHSA-2010-0842.htmlhttp://www.vupen.com/english/advisories/2010/2430http://www.vupen.com/english/advisories/2011/0298https://bugzilla.redhat.com/show_bug.cgi?id=621435http://git.kernel.org/?p=linux/kernel/git/airlied/drm-2.6.git%3Ba=commit%3Bh=1b2f1489633888d4a06028315dc19d65768a1c05http://git.kernel.org/?p=linux/kernel/git/airlied/drm-2.6.git%3Ba=commit%3Bh=b9f0aee83335db1f3915f4e42a5e21b351740afdhttp://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=b9f0aee83335db1f3915f4e42a5e21b351740afdhttp://lists.opensuse.org/opensuse-security-announce/2010-09/msg00004.htmlhttp://lists.opensuse.org/opensuse-security-announce/2010-09/msg00005.htmlhttp://lists.opensuse.org/opensuse-security-announce/2010-11/msg00000.htmlhttp://lists.opensuse.org/opensuse-security-announce/2011-02/msg00000.htmlhttp://secunia.com/advisories/41512http://www.debian.org/security/2010/dsa-2094http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.27.53http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.32.21http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.34.6http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.35.4http://www.mandriva.com/security/advisories?name=MDVSA-2010:198http://www.redhat.com/support/errata/RHSA-2010-0842.htmlhttp://www.vupen.com/english/advisories/2010/2430http://www.vupen.com/english/advisories/2011/0298https://bugzilla.redhat.com/show_bug.cgi?id=621435
2010-09-08
Published