The ucode_ioctl function in intel/io/ucode_drv.c in Sun Solaris 10 and OpenSolaris snv_69 through snv_133, when running on x86 architectures, allows local users to cause a denial of service (panic) via a request with a 0 size value to the UCODE_GET_VERSION IOCTL, which triggers a NULL pointer dereference in the ucode_get_rev function, related to retrieval of the microcode revision.
References
Configurations
Configuration 1 (hide)
|
Information
Published : 2010-02-03 10:30
Updated : 2018-10-10 12:52
NVD link : CVE-2010-0453
Mitre link : CVE-2010-0453
JSON object : View
CWE
CWE-20
Improper Input Validation
Products Affected
sun
- opensolaris
- solaris