PT-2019-6599 · Linux · Linux Kernel
CVSS v3.1
7.8
Alta
| Vetor | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel versions prior to 2.6.34
Description
A range check issue in drivers/gpu/drm/radeon/atombios.c could cause an off by one (buffer overflow) problem. The issue is disputed by at least one Linux maintainer, who believes it should be rejected because the value is hard coded and not user-controllable where it is used.
Recommendations
For Linux kernel versions prior to 2.6.34, update to version 2.6.34 or later to resolve the issue. As a temporary workaround, consider restricting access to the atombios.c module to minimize the risk of exploitation.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Linux Kernel