cbcvebase.
CVE-2011-2022
published 2011-05-09

CVE-2011-2022: The agp_generic_remove_memory function in drivers/char/agp/generic.c in the Linux kernel before 2.6.38.5 does not validate a certain start parameter, which…

PriorityP422medium6.9CVSS 2.0
AVLACMAuNCCICAC
EPSS
0.38%
30.3th percentile
The agp_generic_remove_memory function in drivers/char/agp/generic.c in the Linux kernel before 2.6.38.5 does not validate a certain start parameter, which allows local users to gain privileges or cause a denial of service (system crash) via a crafted AGPIOC_UNBIND agp_ioctl ioctl call, a different vulnerability than CVE-2011-1745.

Affected

8 ranges
VendorProductVersion rangeFixed in
googlechrome_chrome
linuxlinux_kernel< 2.6.38.52.6.38.5
redhatenterprise_linux
redhatenterprise_linux_aus
redhatenterprise_linux_desktop
redhatenterprise_linux_eus
redhatenterprise_linux_server
redhatenterprise_linux_workstation

CVSS provenance

nvdv2.06.9MEDIUMAV:L/AC:M/Au:N/C:C/I:C/A:C
cisa9.8CRITICAL
vendor_redhat7.8HIGH
vendor_ubuntu7.2HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.