Описание
alsa-lib through 1.2.16.1 contains a stack buffer overflow in the __snd_ctl_ascii_elem_id_parse() function that writes one byte past a 64-byte buffer when parsing a name= field with 64 or more characters. Attackers can supply a long control-element identifier string through saved state files or command-line arguments to overwrite adjacent stack memory and crash the calling process.
A flaw was found in alsa-lib. This vulnerability is an off-by-one stack buffer overflow in the __snd_ctl_ascii_elem_id_parse() function. A local attacker can exploit this by supplying a specially crafted, long control-element identifier string through saved state files or command-line arguments. This can cause the application to write one byte past a 64-byte buffer, leading to adjacent stack memory corruption and a crash of the calling process, resulting in a Denial of Service (DoS).
Меры по смягчению последствий
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 10 | alsa-lib | Fix deferred | ||
| Red Hat Enterprise Linux 6 | alsa-lib | Out of support scope | ||
| Red Hat Enterprise Linux 7 | alsa-lib | Fix deferred | ||
| Red Hat Enterprise Linux 8 | alsa-lib | Fix deferred | ||
| Red Hat Enterprise Linux 9 | alsa-lib | Fix deferred | ||
| Red Hat Hardened Images | alsa-lib | Affected |
Показывать по
Ссылки на источники
Дополнительная информация
Статус:
EPSS
6.1 Medium
CVSS3
Связанные уязвимости
alsa-lib through 1.2.16.1 contains a stack buffer overflow in the __snd_ctl_ascii_elem_id_parse() function that writes one byte past a 64-byte buffer when parsing a name= field with 64 or more characters. Attackers can supply a long control-element identifier string through saved state files or command-line arguments to overwrite adjacent stack memory and crash the calling process.
alsa-lib through 1.2.16.1 contains a stack buffer overflow in the __snd_ctl_ascii_elem_id_parse() function that writes one byte past a 64-byte buffer when parsing a name= field with 64 or more characters. Attackers can supply a long control-element identifier string through saved state files or command-line arguments to overwrite adjacent stack memory and crash the calling process.
alsa-lib through 1.2.16.1 contains a stack buffer overflow in the __sn ...
alsa-lib through 1.2.16.1 contains a stack buffer overflow in the __snd_ctl_ascii_elem_id_parse() function that writes one byte past a 64-byte buffer when parsing a name= field with 64 or more characters. Attackers can supply a long control-element identifier string through saved state files or command-line arguments to overwrite adjacent stack memory and crash the calling process.
Уязвимость функции __snd_ctl_ascii_elem_id_parse() библиотеки для взаимодействия со звуковыми драйверами ядра Alsa-lib, позволяющая нарушителю вызвать отказ в обслуживании
EPSS
6.1 Medium
CVSS3