On 32-bit systems, a large args->buffer_count from userspace via ioctl
may overflow the allocation size, leading to out-of-bounds access.
This vulnerability was introduced in commit
|
||
---|---|---|
.. | ||
drm | ||
stub | ||
vga | ||
Makefile |
On 32-bit systems, a large args->buffer_count from userspace via ioctl
may overflow the allocation size, leading to out-of-bounds access.
This vulnerability was introduced in commit
|
||
---|---|---|
.. | ||
drm | ||
stub | ||
vga | ||
Makefile |