Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2016-4578

Опубликовано: 23 мая 2016
Источник: debian
EPSS Низкий

Описание

sound/core/timer.c in the Linux kernel through 4.6 does not initialize certain r1 data structures, which allows local users to obtain sensitive information from kernel stack memory via crafted use of the ALSA timer interface, related to the (1) snd_timer_user_ccallback and (2) snd_timer_user_tinterrupt functions.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
linuxfixed4.5.5-1package

Примечания

  • https://github.com/torvalds/linux/commit/9a47e9cff994f37f7f0dbd9ae23740d0f64f9fe6

  • https://github.com/torvalds/linux/commit/e4ec8cc8039a7063e24204299b462bd1383184a5

EPSS

Процентиль: 50%
0.00264
Низкий

Связанные уязвимости

CVSS3: 5.5
ubuntu
около 9 лет назад

sound/core/timer.c in the Linux kernel through 4.6 does not initialize certain r1 data structures, which allows local users to obtain sensitive information from kernel stack memory via crafted use of the ALSA timer interface, related to the (1) snd_timer_user_ccallback and (2) snd_timer_user_tinterrupt functions.

redhat
около 9 лет назад

sound/core/timer.c in the Linux kernel through 4.6 does not initialize certain r1 data structures, which allows local users to obtain sensitive information from kernel stack memory via crafted use of the ALSA timer interface, related to the (1) snd_timer_user_ccallback and (2) snd_timer_user_tinterrupt functions.

CVSS3: 5.5
nvd
около 9 лет назад

sound/core/timer.c in the Linux kernel through 4.6 does not initialize certain r1 data structures, which allows local users to obtain sensitive information from kernel stack memory via crafted use of the ALSA timer interface, related to the (1) snd_timer_user_ccallback and (2) snd_timer_user_tinterrupt functions.

CVSS3: 5.5
github
около 3 лет назад

sound/core/timer.c in the Linux kernel through 4.6 does not initialize certain r1 data structures, which allows local users to obtain sensitive information from kernel stack memory via crafted use of the ALSA timer interface, related to the (1) snd_timer_user_ccallback and (2) snd_timer_user_tinterrupt functions.

oracle-oval
больше 8 лет назад

ELSA-2016-3646: Unbreakable Enterprise kernel security update (IMPORTANT)

EPSS

Процентиль: 50%
0.00264
Низкий