The agp_generic_remove_memory function in drivers/char/agp/generic.c in the Linux kernel before 2.6.38.5 does not validate a certain start parameter, which allows local users to gain privileges or cause a denial of service (system crash) via a crafted AGPIOC_UNBIND agp_ioctl ioctl call, a different vulnerability than CVE-2011-1745.
Product | Vendor | Version |
---|---|---|
n/a | n/a | < 6b3f7e4b10f343f05b5fb513b07a9168fbf1172e |