7.8
CVSSv2

CVE-2013-7445

Published: 16/10/2015 Updated: 16/10/2015
CVSS v2 Base Score: 7.8 | Impact Score: 6.9 | Exploitability Score: 10
VMScore: 695
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C

Vulnerability Summary

The Direct Rendering Manager (DRM) subsystem in the Linux kernel up to and including 4.x mishandles requests for Graphics Execution Manager (GEM) objects, which allows context-dependent malicious users to cause a denial of service (memory consumption) via an application that processes graphics data, as demonstrated by JavaScript code that creates many CANVAS elements for rendering by Chrome or Firefox.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

linux linux kernel 4.0.2

linux linux kernel 4.0.3

linux linux kernel 4.1.1

linux linux kernel 4.1.2

linux linux kernel 4.1.3

linux linux kernel 4.1.4

linux linux kernel 4.0.4

linux linux kernel 4.0.5

linux linux kernel 4.1.10

linux linux kernel 4.2.1

linux linux kernel 4.2.2

linux linux kernel 4.2.3

linux linux kernel

linux linux kernel 4.0.7

linux linux kernel 4.0.9

linux linux kernel 4.1.5

linux linux kernel 4.1.7

linux linux kernel 4.1.9

linux linux kernel 4.0.1

linux linux kernel 4.0.6

linux linux kernel 4.0.8

linux linux kernel 4.1.6

linux linux kernel 4.1.8

Vendor Advisories

Debian Bug report logs - #1000886 CVE-2013-7445: Direct Rendering Manager (DRM) subsystem in the Linux Kernel through 4x mishandles requests for GEM object Package: src:linux; Maintainer for src:linux is Debian Kernel Team <debian-kernel@listsdebianorg>; Reported by: "Jeremiah C Foster" <jeremiah@jeremiahfostercom> ...
The Direct Rendering Manager (DRM) subsystem in the Linux kernel through 4x mishandles requests for Graphics Execution Manager (GEM) objects, which allows context-dependent attackers to cause a denial of service (memory consumption) via an application that processes graphics data, as demonstrated by JavaScript code that creates many CANVAS element ...