Description
The snd_hdspm_hwdep_ioctl function in sound/pci/rme9652/hdspm.c in the Linux kernel before 2.6.36-rc6 does not initialize a certain structure, which allows local users to obtain potentially sensitive information from kernel stack memory via an SNDRV_HDSPM_IOCTL_GET_CONFIG_INFO ioctl call.
References (28)
... and 8 more
Scores
EPSS
0.0008
EPSS Percentile
23.7%
Details
CWE
CWE-909
Status
published
Products (10)
debian/debian_linux
5.0
linux/linux_kernel
2.6.36 (6 CPE variants)
linux/linux_kernel
< 2.6.36
opensuse/opensuse
11.2
opensuse/opensuse
11.3
suse/linux_enterprise_desktop
10 sp3
suse/linux_enterprise_real_time_extension
11 sp1
suse/linux_enterprise_server
9
suse/linux_enterprise_server
10 sp3
suse/linux_enterprise_software_development_kit
10 sp3
Published
Nov 30, 2010
Tracked Since
Feb 18, 2026