git.kernel.orgConfirmation
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit?id=9a47e9cff994f37f7f0dbd9ae23740d0f64f9fe6 CVE-2016-4578
MEDIUM
Linux Kernel 4.4 (Ubuntu 16.04) - 'snd_timer_user_ccallback()' Kernel Pointer Leak
Record summary
CVE-2016-4578 has a selected CVSS score of 5.5 (medium); EIP currently links 1 catalogued exploit.
Description
sound/core/timer.c in the Linux kernel through 4.6 does not initialize certain r1 data structures, which allows local users to obtain sensitive information from kernel stack memory via crafted use of the ALSA timer interface, related to the (1) snd_timer_user_ccallback and (2) snd_timer_user_tinterrupt functions.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBLinux Kernel 4.4 (Ubuntu 16.04) - 'snd_timer_user_ccallback()' Kernel Pointer LeakExploitDB exploitby wally0813Not analyzed1 file
References
Showing 12 of 32git.kernel.orgConfirmation
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit?id=e4ec8cc8039a7063e24204299b462bd1383184a5 openSUSE-SU-2016:1641Vendor advisory
http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00044.html SUSE-SU-2016:1672Vendor advisory
http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00052.html SUSE-SU-2016:1690Vendor advisory
http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00054.html SUSE-SU-2016:1937Vendor advisory
http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00000.html SUSE-SU-2016:1985Vendor advisory
http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00007.html SUSE-SU-2016:2105Vendor advisory
http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00044.html openSUSE-SU-2016:2184Vendor advisory
http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00055.html RHSA-2016:2574Vendor advisory
http://rhn.redhat.com/errata/RHSA-2016-2574.html RHSA-2016:2584Vendor advisory
http://rhn.redhat.com/errata/RHSA-2016-2584.html DSA-3607Vendor advisory
http://www.debian.org/security/2016/dsa-3607