CVE-2013-7445

Linux Kernel < 4.0.0 - Denial of Service via DRM GEM Object Requests

Title source: llm
STIX 2.1

Description

The Direct Rendering Manager (DRM) subsystem in the Linux kernel through 4.x mishandles requests for Graphics Execution Manager (GEM) objects, which allows context-dependent attackers to cause a denial of service (memory consumption) via an application that processes graphics data, as demonstrated by JavaScript code that creates many CANVAS elements for rendering by Chrome or Firefox.

References (1)

Core 1
Core References
Issue Tracking x_refsource_misc
https://bugzilla.kernel.org/show_bug.cgi?id=60533

Scores

EPSS 0.0273
EPSS Percentile 84.7%

Details

CWE
CWE-399
Status published
Products (23)
linux/linux_kernel 4.0.1
linux/linux_kernel 4.0.2
linux/linux_kernel 4.0.3
linux/linux_kernel 4.0.4
linux/linux_kernel 4.0.5
linux/linux_kernel 4.0.6
linux/linux_kernel 4.0.7
linux/linux_kernel 4.0.8
linux/linux_kernel 4.0.9
linux/linux_kernel 4.1.1
... and 13 more
Published Oct 16, 2015
Tracked Since Feb 18, 2026