Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
drivers/media/video/v4l2-compat-ioctl32.c in the Video4Linux (V4L) implementation in the Linux kernel before 2.6.36 on 64-bit platforms does not validate the destination of a memory copy operation, which allows local users to write to arbitrary kernel memory locations, and consequently gain privileges, via a VIDIOCSTUNER ioctl call on a /dev/video device, followed by a VIDIOCSMICROCODE ioctl call on this device.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Linux Kernel Video4Linux输入验证错误漏洞
Vulnerability Description
Linux Kernel 是开放源码操作系统Linux所使用的内核。 基于64位平台的Linux kernel 2.6.36之前版本中Video4Linux(V4L)实现中的drivers/media/video/v4l2-compat-ioctl32.c文件无法验证内存复制操作的目的位置。本地用户可以借助在/dev/video路径设备的VIDIOCSTUNER输入输出控制调用,以及之后对这个设备的VIDIOCSTUNER输入输出控制调用向任意内核内存地址写入数据,以及获得特权。
CVSS Information
N/A
Vulnerability Type
N/A