CVE-2010-2963
Linux Kernel <2.6.36 - Privilege Escalation
Title source: llmDescription
drivers/media/video/v4l2-compat-ioctl32.c in the Video4Linux (V4L) implementation in the Linux kernel before 2.6.36 on 64-bit platforms does not validate the destination of a memory copy operation, which allows local users to write to arbitrary kernel memory locations, and consequently gain privileges, via a VIDIOCSTUNER ioctl call on a /dev/video device, followed by a VIDIOCSMICROCODE ioctl call on this device.
Exploits (1)
References (14)
Scores
EPSS
0.0011
EPSS Percentile
28.4%
Details
CWE
CWE-20
Status
published
Products (13)
canonical/ubuntu_linux
6.06
canonical/ubuntu_linux
8.04
canonical/ubuntu_linux
9.04
canonical/ubuntu_linux
9.10
canonical/ubuntu_linux
10.04
canonical/ubuntu_linux
10.10
debian/debian_linux
5.0
fedoraproject/fedora
13
linux/linux_kernel
< 2.6.36
opensuse/opensuse
11.2
... and 3 more
Published
Nov 26, 2010
Tracked Since
Feb 18, 2026