CVE-2010-3448
Advisory lineage Upstream: 0 Downstream: 2
Downstream
Modified
Published: 03 Jan 2011, 19:26
Last modified:07 Aug 2024, 03:11
Vulnerability Summary
Overall Risk (default)
low
20/100 CVSS Score
4.9 MEDIUM
v2.0 (nvd)
EPSS Score
0.1% LOW
0% probability +0.05%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected
Timeline
03 Jan 2011, 19:26
Published
Vulnerability first disclosed
07 Aug 2024, 03:11
Last Modified
Vulnerability information updated
Description
drivers/platform/x86/thinkpad_acpi.c in the Linux kernel before 2.6.34 on ThinkPad devices, when the X.Org X server is used, does not properly restrict access to the video output control state, which allows local users to cause a denial of service (system hang) via a (1) read or (2) write operation.
CVSS Metrics
- v2.0•MEDIUM•Score: 4.9AV:L/AC:L/Au:N/C:N/I:N/A:C
EPSS Trends
Current EPSS score: 0.10%• Percentile: 27%
Techniques & Countermeasures
- CWE-264•Permissions, Privileges, and Access Controls
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Affected Systems
- linux•linux_kernel
< 2.6.34
References (11)
- http://openwall.com/lists/oss-security/2010/09/28/1
- http://openwall.com/lists/oss-security/2010/09/29/7
- https://bugzilla.redhat.com/show_bug.cgi?id=652122
- http://openwall.com/lists/oss-security/2010/09/30/1
- http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=565790
- http://openwall.com/lists/oss-security/2010/06/23/2
- https://exchange.xforce.ibmcloud.com/vulnerabilities/64580
- http://openwall.com/lists/oss-security/2010/09/30/6
- http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=b525c06cdbd8a3963f0173ccd23f9147d4c384b5
- http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.34
- http://www.debian.org/security/2010/dsa-2126