Integer overflow in the drm_mode_dirtyfb_ioctl function in drivers/gpu/drm/drm_crtc.c in the Direct Rendering Manager (DRM) subsystem in the Linux kernel before 3.1.5 allows local users to gain privileges or cause a denial of service (memory corruption) via a crafted ioctl call.
| Software | From | Fixed in |
|---|---|---|
| linux / linux_kernel | - | 3.0.13 |
| linux / linux_kernel | 3.1 | 3.1.5 |
| canonical / ubuntu_linux | 10.04 | 10.04.x |