Upstream information
Description
Integer overflow in the drm_mode_dirtyfb_ioctl function in drivers/gpu/drm/drm_crtc.c in the Direct Rendering Manager (DRM) subsystem in the Linux kernel before 3.1.5 allows local users to gain privileges or cause a denial of service (memory corruption) via a crafted ioctl call.NVD CVSS v2 Base Score: 7.2 (AV:L/AC:L/Au:N/C:C/I:C/A:C)
Novell/SUSE information
Note from the SUSE Security Team
This vulnerability was introduced in 2.6.33-rc2 and was not backported to older products. So SUSE Linux Enterprise 10 and older products are not affected by this problem.,This vulnerability was introduced in 2.6.39-rc6 and was not backported to older products. So SUSE Linux Enterprise Server 11 SP1, SUSE Linux Enterprise 10 and older products are not affected by this problem. Novell Bugzilla entry: 740745 SUSE Security Advisories:- openSUSE-SU-2012:0799-1, published Thu, 28 Jun 2012 10:08:31 +0200 (CEST)
- openSUSE-SU-2012:1439-1, published Mon, 5 Nov 2012 10:09:03 +0100 (CET)
List of released packages
| Product(s) | Fixed package version(s) | References |
|---|---|---|
| SUSE Linux Enterprise Real Time 11 SP1 |
| slert11-sp1.x86-64 SAT Patch Nr: 6677 |
