Database/Kernel, userspace & hypervisor
Intel i915 graphics kernel-mode driver for Linux (< 5.0): Insufficient input validation in the i915 kernel-mode driver
CVSS 7.8CVE-2019-11085Kernel, userspace & hypervisorcurated
Impact
Insufficient input validation in the i915 kernel-mode driver gives a local authenticated user a path to privilege escalation. Old but still present on long-lived nodes running frozen enterprise kernels.
Who can reach it
Local user with access to the i915 DRM device - including any container granted /dev/dri.
What to do
Move to a fixed kernel (5.0+ upstream or a distro backport) and reboot the node. Kernel-only fix, no firmware.
References
Related entries
- Linux kernel (ptrace): Broken permission and object lifetime handling for PTRACE_TRACEME, local rootCVE-2019-13272 · Linux kernel (ptrace)High
- AMD Radeon Kernel Mode driver - Escape 0x2000c00 call handler: A low-privileged attacker can drive the RadeonCVE-2020-12964 · AMD Radeon Kernel Mode driver - Escape 0x2000c00 call handlerHigh
- Linux i915 GPU kernel driver: A use-after-free in the i915 GPU kernel driver. The general shape is that a GPU object isCVE-2020-7053 · Linux i915 GPU kernel driverHigh
- Linux kernel (netfilter x_tables): Heap out-of-bounds write in xt_compat_target_from_user()CVE-2021-22555 · Linux kernel (netfilter x_tables)High
- sudo: Baron Samedit: heap overflow in sudo argument parsing, root from any local accountCVE-2021-3156 · sudoHigh
- Linux kernel (seq_file / fs layer): Sequoia: size_t-to-int conversion in the filesystem layer, local root on defaultCVE-2021-33909 · Linux kernel (seq_file / fs layer)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.