Back to search
CVE-2008-3831
Published: Oct 20, 2008
Modified: Aug 7, 2024
PUBLISHED
Description
The i915 driver in (1) drivers/char/drm/i915_dma.c in the Linux kernel 2.6.24 on Debian GNU/Linux and (2) sys/dev/pci/drm/i915_drv.c in OpenBSD does not restrict the DRM_I915_HWS_ADDR ioctl to the Direct Rendering Manager (DRM) master, which allows local users to cause a denial of service (memory corruption) via a crafted ioctl call, related to absence of the DRM_MASTER and DRM_ROOT_ONLY flags in the ioctl's configuration.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
245846
vendor-advisory
x_refsource_SUNALERT
DSA-1655
vendor-advisory
x_refsource_DEBIAN
MDVSA-2008:224
vendor-advisory
x_refsource_MANDRIVA
USN-659-1
vendor-advisory
x_refsource_UBUNTU
RHSA-2009:0009
vendor-advisory
x_refsource_REDHAT
1021065
vdb-entry
x_refsource_SECTRACK
FEDORA-2008-8929
vendor-advisory
x_refsource_FEDORA
33586
third-party-advisory
x_refsource_SECUNIA
32709
third-party-advisory
x_refsource_SECUNIA
32918
third-party-advisory
x_refsource_SECUNIA
USN-679-1
vendor-advisory
x_refsource_UBUNTU
http://wiki.rpath.com/Advisories:rPSA-2008-0316
x_refsource_CONFIRM
http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0316
x_refsource_CONFIRM
oval:org.mitre.oval:def:11542
vdb-entry
signature
x_refsource_OVAL
RHSA-2008:1017
vendor-advisory
x_refsource_REDHAT
[source-changes] 20081017 CVS: cvs.openbsd.org: src
mailing-list
x_refsource_MLIST
32386
third-party-advisory
x_refsource_SECUNIA
31792
vdb-entry
x_refsource_BID
FEDORA-2008-8980
vendor-advisory
x_refsource_FEDORA
http://www.openbsd.org/cgi-bin/cvsweb/src/sys/dev/pci/drm/i915_drv.c
x_refsource_CONFIRM
33182
third-party-advisory
x_refsource_SECUNIA
20081112 rPSA-2008-0316-1 kernel
mailing-list
x_refsource_BUGTRAQ
32315
third-party-advisory
x_refsource_SECUNIA
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now