LOW · 1.9

CVE-2010-2803

The drm_ioctl function in drivers/gpu/drm/drm_drv.c in the Direct Rendering Manager (DRM) subsystem in the Linux kernel before 2.6.27.53, 2.6.32.x before 2.6.32.21, 2.6.34.x before 2.6.34.6, and 2.6.3...

Vulnerability Description

The drm_ioctl function in drivers/gpu/drm/drm_drv.c in the Direct Rendering Manager (DRM) subsystem in the Linux kernel before 2.6.27.53, 2.6.32.x before 2.6.32.21, 2.6.34.x before 2.6.34.6, and 2.6.35.x before 2.6.35.4 allows local users to obtain potentially sensitive information from kernel memory by requesting a large memory-allocation amount.

CVSS Score

1.9

LOW

AV:L/AC:M/Au:N/C:P/I:N/A:N
Confidentiality
PARTIAL
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
LinuxLinux Kernel< 2.6.27.53
DebianDebian Linux5.0
OpensuseOpensuse11.1
SuseLinux Enterprise Desktop11
SuseLinux Enterprise High Availability Extension11
SuseLinux Enterprise Real Time11
SuseLinux Enterprise Server11

Related Weaknesses (CWE)

References

FAQ

What is CVE-2010-2803?

CVE-2010-2803 is a vulnerability with a CVSS score of 1.9 (LOW). The drm_ioctl function in drivers/gpu/drm/drm_drv.c in the Direct Rendering Manager (DRM) subsystem in the Linux kernel before 2.6.27.53, 2.6.32.x before 2.6.32.21, 2.6.34.x before 2.6.34.6, and 2.6.3...

How severe is CVE-2010-2803?

CVE-2010-2803 has been rated LOW with a CVSS base score of 1.9/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2010-2803?

Check the references section above for vendor advisories and patch information. Affected products include: Linux Linux Kernel, Debian Debian Linux, Opensuse Opensuse, Suse Linux Enterprise Desktop, Suse Linux Enterprise High Availability Extension.