Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2017-13167

Опубликовано: 09 фев. 2016
Источник: redhat
CVSS3: 3.6

Описание

An elevation of privilege vulnerability in the kernel sound timer. Product: Android. Versions: Android kernel. Android ID A-37240993.

A race condition was found in the Linux kernel's sound timer code in the snd_timer_user_read() function in the sound/core/timer.c file. An unprivileged attacker can exploit the race condition to cause an out-of-bound access which may lead to a system crash or other unspecified impact. Due to the nature of the flaw, privilege escalation cannot be fully ruled out.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5kernelWill not fix
Red Hat Enterprise Linux 6kernelAffected
Red Hat Enterprise Linux 7kernel-altNot affected
Red Hat Enterprise Linux 8kernelNot affected
Red Hat Enterprise MRG 2realtime-kernelNot affected
Red Hat Enterprise Linux 7kernel-rtFixedRHSA-2016:258403.11.2016
Red Hat Enterprise Linux 7kernelFixedRHSA-2016:257403.11.2016
Red Hat Enterprise MRG 2kernel-rtFixedRHSA-2017:011317.01.2017

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-362
https://bugzilla.redhat.com/show_bug.cgi?id=1568821kernel: sound: a race condition in the kernel sound timer in snd_timer_user_read()

3.6 Low

CVSS3

Связанные уязвимости

CVSS3: 7.8
ubuntu
около 8 лет назад

An elevation of privilege vulnerability in the kernel sound timer. Product: Android. Versions: Android kernel. Android ID A-37240993.

CVSS3: 7.8
nvd
около 8 лет назад

An elevation of privilege vulnerability in the kernel sound timer. Product: Android. Versions: Android kernel. Android ID A-37240993.

CVSS3: 7.8
debian
около 8 лет назад

An elevation of privilege vulnerability in the kernel sound timer. Pro ...

CVSS3: 7.8
github
больше 3 лет назад

An elevation of privilege vulnerability in the kernel sound timer. Product: Android. Versions: Android kernel. Android ID A-37240993.

suse-cvrf
около 8 лет назад

Security update for the Linux Kernel

3.6 Low

CVSS3

Уязвимость CVE-2017-13167