imPC@ndo IT

Tracker / CVE-2009-3620

CVE-2009-3620

High 7.8

The ATI Rage 128 (aka r128) driver in the Linux kernel before 2.6.31-git11 does not properly verify Concurrent Command Engine (CCE) state initialization, which allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly gain privileges via unspecified ioctl calls.

Affected products and versions

canonical ubuntu_linux
fedoraproject fedora
linux linux_kernel · … → 2.6.31.1
opensuse opensuse
redhat mrg_realtime
suse linux_enterprise_debuginfo
suse linux_enterprise_desktop
suse linux_enterprise_server

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References