Synced 30 Sept 2026 20:54 UTC Account
← All products

CVE-2010-2963

MEDIUM severity · CVSS 6.2 · Improper input validation
6.2CVSS MEDIUM

Summary

drivers/media/video/v4l2-compat-ioctl32.c in the Video4Linux (V4L) implementation in the Linux kernel before 2.6.36 on 64-bit platforms does not validate the destination of a memory copy operation, which allows local users to write to arbitrary kernel memory locations, and consequently gain privileges, via a VIDIOCSTUNER ioctl call on a /dev/video device, followed by a VIDIOCSMICROCODE ioctl call on this device.

Impact & exploitability

Attack vectorLocal
Attack complexityHigh
Privileges required—
User interaction—
Confidentiality impact—
Integrity impact—
Availability impact—
Exploit probability (EPSS)1%

AV:L/AC:H/Au:N/C:C/I:C/A:C

Affected products we track (2)

Recommendation

Apply the vendor fix in your normal patch cycle. Open any affected product above for its exact safe version.