{"api_version":"1","generated_at":"2026-07-23T08:33:22+00:00","cve":"CVE-2011-1016","urls":{"html":"https://cve.report/CVE-2011-1016","api":"https://cve.report/api/cve/CVE-2011-1016.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2011-1016","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2011-1016"},"summary":{"title":"CVE-2011-1016","description":"The Radeon GPU drivers in the Linux kernel before 2.6.38-rc5 do not properly validate data related to the AA resolve registers, which allows local users to write to arbitrary memory locations associated with (1) Video RAM (aka VRAM) or (2) the Graphics Translation Table (GTT) via crafted values.","state":"PUBLISHED","assigner":"redhat","published_at":"2011-02-28 16:00:01","updated_at":"2026-04-29 01:13:23"},"problem_types":["CWE-20","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"1.9","severity":"","vector":"AV:L/AC:M/Au:N/C:N/I:P/A:N","data":{"version":"2.0","vectorString":"AV:L/AC:M/Au:N/C:N/I:P/A:N","baseScore":1.9,"accessVector":"LOCAL","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"}}],"references":[{"url":"http://www.securityfocus.com/bid/46557","name":"http://www.securityfocus.com/bid/46557","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"],"title":"Linux Kernel ATI Radeon R300 Local Input Validation Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=fff1ce4dc6113b6fdc4e3a815ca5fd229408f8ef","name":"http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=fff1ce4dc6113b6fdc4e3a815ca5fd229408f8ef","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"kernel/git/torvalds/linux.git - Linux kernel source tree","mime":"text/html","httpstatus":"404","archivestatus":"200"},{"url":"http://openwall.com/lists/oss-security/2011/02/24/11","name":"http://openwall.com/lists/oss-security/2011/02/24/11","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List","Patch","Third Party Advisory"],"title":"oss-security - Re: CVE request: kernel: drm/radeon/kms: check AA\n resolve registers on r300","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/65691","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/65691","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://openwall.com/lists/oss-security/2011/02/24/3","name":"http://openwall.com/lists/oss-security/2011/02/24/3","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List","Patch","Third Party Advisory"],"title":"oss-security - CVE request: kernel: drm/radeon/kms: check AA resolve registers on\n r300","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://openwall.com/lists/oss-security/2011/02/25/4","name":"http://openwall.com/lists/oss-security/2011/02/25/4","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List","Patch","Third Party Advisory"],"title":"oss-security - Re: CVE request: kernel: drm/radeon/kms: check AA\n resolve registers on r300","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=680000","name":"https://bugzilla.redhat.com/show_bug.cgi?id=680000","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Issue Tracking","Patch","Third Party Advisory"],"title":"680000 – (CVE-2011-1016) CVE-2011-1016 kernel: drm/radeon/kms: check AA resolve registers on r300","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.kernel.org/pub/linux/kernel/v2.6/testing/ChangeLog-2.6.38-rc5","name":"http://www.kernel.org/pub/linux/kernel/v2.6/testing/ChangeLog-2.6.38-rc5","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"],"title":"404: File not found","mime":"text/plain","httpstatus":"404","archivestatus":"200"},{"url":"http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=fff1ce4dc6113b6fdc4e3a815ca5fd229408f8ef","name":"CONFIRM:http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=fff1ce4dc6113b6fdc4e3a815ca5fd229408f8ef","refsource":"MITRE","tags":[],"title":"kernel/git/torvalds/linux.git - Linux kernel source tree","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2011-1016","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2011-1016","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2011","cve_id":"1016","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"linux","cpe5":"linux_kernel","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2011","cve_id":"1016","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"linux","cpe5":"linux_kernel","cpe6":"2.6.38","cpe7":"-","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2011","cve_id":"1016","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"linux","cpe5":"linux_kernel","cpe6":"2.6.38","cpe7":"rc1","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2011","cve_id":"1016","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"linux","cpe5":"linux_kernel","cpe6":"2.6.38","cpe7":"rc2","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2011","cve_id":"1016","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"linux","cpe5":"linux_kernel","cpe6":"2.6.38","cpe7":"rc3","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2011","cve_id":"1016","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"linux","cpe5":"linux_kernel","cpe6":"2.6.38","cpe7":"rc4","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-06T22:14:27.098Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"[oss-security] 20110224 CVE request: kernel: drm/radeon/kms: check AA resolve registers on r300","tags":["mailing-list","x_refsource_MLIST","x_transferred"],"url":"http://openwall.com/lists/oss-security/2011/02/24/3"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.kernel.org/pub/linux/kernel/v2.6/testing/ChangeLog-2.6.38-rc5"},{"name":"kernel-atiradeon-sec-bypass(65691)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/65691"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=fff1ce4dc6113b6fdc4e3a815ca5fd229408f8ef"},{"name":"[oss-security] 20110224 Re: CVE request: kernel: drm/radeon/kms: check AA resolve registers on r300","tags":["mailing-list","x_refsource_MLIST","x_transferred"],"url":"http://openwall.com/lists/oss-security/2011/02/24/11"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://bugzilla.redhat.com/show_bug.cgi?id=680000"},{"name":"[oss-security] 20110225 Re: CVE request: kernel: drm/radeon/kms: check AA resolve registers on r300","tags":["mailing-list","x_refsource_MLIST","x_transferred"],"url":"http://openwall.com/lists/oss-security/2011/02/25/4"},{"name":"46557","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/46557"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2011-02-15T00:00:00.000Z","descriptions":[{"lang":"en","value":"The Radeon GPU drivers in the Linux kernel before 2.6.38-rc5 do not properly validate data related to the AA resolve registers, which allows local users to write to arbitrary memory locations associated with (1) Video RAM (aka VRAM) or (2) the Graphics Translation Table (GTT) via crafted values."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-08-16T14:57:01.000Z","orgId":"53f830b8-0a3f-465b-8143-3b8a9948e749","shortName":"redhat"},"references":[{"name":"[oss-security] 20110224 CVE request: kernel: drm/radeon/kms: check AA resolve registers on r300","tags":["mailing-list","x_refsource_MLIST"],"url":"http://openwall.com/lists/oss-security/2011/02/24/3"},{"tags":["x_refsource_CONFIRM"],"url":"http://www.kernel.org/pub/linux/kernel/v2.6/testing/ChangeLog-2.6.38-rc5"},{"name":"kernel-atiradeon-sec-bypass(65691)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/65691"},{"tags":["x_refsource_CONFIRM"],"url":"http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=fff1ce4dc6113b6fdc4e3a815ca5fd229408f8ef"},{"name":"[oss-security] 20110224 Re: CVE request: kernel: drm/radeon/kms: check AA resolve registers on r300","tags":["mailing-list","x_refsource_MLIST"],"url":"http://openwall.com/lists/oss-security/2011/02/24/11"},{"tags":["x_refsource_CONFIRM"],"url":"https://bugzilla.redhat.com/show_bug.cgi?id=680000"},{"name":"[oss-security] 20110225 Re: CVE request: kernel: drm/radeon/kms: check AA resolve registers on r300","tags":["mailing-list","x_refsource_MLIST"],"url":"http://openwall.com/lists/oss-security/2011/02/25/4"},{"name":"46557","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/46557"}]}},"cveMetadata":{"assignerOrgId":"53f830b8-0a3f-465b-8143-3b8a9948e749","assignerShortName":"redhat","cveId":"CVE-2011-1016","datePublished":"2011-02-28T15:00:00.000Z","dateReserved":"2011-02-14T00:00:00.000Z","dateUpdated":"2024-08-06T22:14:27.098Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2011-02-28 16:00:01","lastModifiedDate":"2026-04-29 01:13:23","problem_types":["CWE-20","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:L/AC:M/Au:N/C:N/I:P/A:N","baseScore":1.9,"accessVector":"LOCAL","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"LOW","exploitabilityScore":3.4,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"2.6.38","matchCriteriaId":"9988A98F-3440-467E-8ADA-1E413DC25C21"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:2.6.38:-:*:*:*:*:*:*","matchCriteriaId":"985DC743-744A-429F-8098-EFCC91DFB6F7"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:2.6.38:rc1:*:*:*:*:*:*","matchCriteriaId":"2DDCB342-4F5F-4BF1-9624-882BBC57330D"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:2.6.38:rc2:*:*:*:*:*:*","matchCriteriaId":"C3AB4113-BF83-4587-8A85-0E4FECEE7D9B"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:2.6.38:rc3:*:*:*:*:*:*","matchCriteriaId":"4B57F5AD-A697-4090-89B9-81BC12993A1A"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:2.6.38:rc4:*:*:*:*:*:*","matchCriteriaId":"CA141BCB-A705-4DF5-9EED-746B62C86111"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2011","CveId":"1016","Ordinal":"1","Title":"CVE-2011-1016","CVE":"CVE-2011-1016","Year":"2011"},"notes":[{"CveYear":"2011","CveId":"1016","Ordinal":"1","NoteData":"The Radeon GPU drivers in the Linux kernel before 2.6.38-rc5 do not properly validate data related to the AA resolve registers, which allows local users to write to arbitrary memory locations associated with (1) Video RAM (aka VRAM) or (2) the Graphics Translation Table (GTT) via crafted values.","Type":"Description","Title":"CVE-2011-1016"},{"CveYear":"2011","CveId":"1016","Ordinal":"2","NoteData":"2011-02-28","Type":"Other","Title":"Published"},{"CveYear":"2011","CveId":"1016","Ordinal":"3","NoteData":"2017-08-16","Type":"Other","Title":"Modified"}]}}}