The dvb_ca_ioctl function in drivers/media/dvb/ttpci/av7110_ca.c in the Linux kernel before 2.6.38-rc2 does not check the sign of a certain integer field, which allows local users to cause a denial of service (memory corruption) or possibly have unspecified other impact via a negative value.
AV:L/AC:L/Au:N/C:C/I:C/A:C
This vulnerability has a 0.40% probability of being exploited in the next 30 days, ranking higher than 32% of all scored CVEs.