cbcvebase.
CVE-2011-2022
published 2011-05-09

CVE-2011-2022: The agp_generic_remove_memory function in drivers/char/agp/generic.c in the Linux kernel before 2.6.38.5 does not validate a certain start parameter, which…

medium6.9CVSS 3.1
AVLACMAuNCCICAC
The agp_generic_remove_memory function in drivers/char/agp/generic.c in the Linux kernel before 2.6.38.5 does not validate a certain start parameter, which allows local users to gain privileges or cause a denial of service (system crash) via a crafted AGPIOC_UNBIND agp_ioctl ioctl call, a different vulnerability than CVE-2011-1745.

Affected

9 ranges
VendorProductVersion rangeFixed in
googlechrome_chrome
linuxlinux_kernel< 2.6.38.52.6.38.5
msrcmicrosoft_edge
redhatenterprise_linux
redhatenterprise_linux_aus
redhatenterprise_linux_desktop
redhatenterprise_linux_eus
redhatenterprise_linux_server
redhatenterprise_linux_workstation

CVSS provenance

nvd6.9MEDIUMAV:L/AC:M/Au:N/C:C/I:C/A:C
cisa9.8CRITICAL