The Radeon GPU drivers in the Linux kernel before 2.6.38-rc5 do not properly validate data related to the AA resolve registers, which allows local users to write to arbitrary memory locations associated with (1) Video RAM (aka VRAM) or (2) the Graphics Translation Table (GTT) via crafted values.
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
Link | Tags |
---|---|
http://openwall.com/lists/oss-security/2011/02/24/3 | mailing list third party advisory patch |
http://www.kernel.org/pub/linux/kernel/v2.6/testing/ChangeLog-2.6.38-rc5 | broken link |
https://exchange.xforce.ibmcloud.com/vulnerabilities/65691 | vdb entry third party advisory |
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=fff1ce4dc6113b6fdc4e3a815ca5fd229408f8ef | |
http://openwall.com/lists/oss-security/2011/02/24/11 | mailing list third party advisory patch |
https://bugzilla.redhat.com/show_bug.cgi?id=680000 | issue tracking third party advisory patch |
http://openwall.com/lists/oss-security/2011/02/25/4 | mailing list third party advisory patch |
http://www.securityfocus.com/bid/46557 | vdb entry third party advisory |