CVE-2011-1013

Integer signedness error in the drm_modeset_ctl function in (1) drivers/gpu/drm/drm_irq.c in the Direct Rendering Manager (DRM) subsystem in the Linux kernel before 2.6.38 and (2) sys/dev/pci/drm/drm_irq.c in the kernel in OpenBSD before 4.9 allows local users to trigger out-of-bounds write operations, and consequently cause a denial of service (system crash) or possibly have unspecified other impact, via a crafted num_crtcs (aka vb_num) structure member in an ioctl argument.
Configurations

Configuration 1 (hide)

cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

Configuration 2 (hide)

cpe:2.3:o:openbsd:openbsd:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2011-05-09 19:55

Updated : 2024-02-28 11:41


NVD link : CVE-2011-1013

Mitre link : CVE-2011-1013

CVE.ORG link : CVE-2011-1013


JSON object : View

Products Affected

openbsd

  • openbsd

linux

  • linux_kernel
CWE
CWE-787

Out-of-bounds Write