Back

MEDIUM

kernel: buffer overflow in OSS load_mixer_volumes

Published Jan 13, 2011

Description

The load_mixer_volumes function in sound/oss/soundcard.c in the OSS sound subsystem in the Linux kernel before 2.6.37 incorrectly expects that a certain name field ends with a '\0' character, which allows local users to conduct buffer overflow attacks and gain privileges, or possibly obtain sensitive information from kernel memory, via a SOUND_MIXER_SETLEVELS ioctl call.

Affected products

Remediation

Red Hat statement

Not vulnerable. This issue did not affect the versions of Linux kernel as shipped with Red Hat Enterprise Linux 4, 5, 6 and Red Hat Enterprise MRG as they did not provide support for Open Sound System (OSS).

Metrics

References (14)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Jan 13, 2011
Updated Aug 7, 2024
Reserved Dec 9, 2010
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Important
Public date Dec 29, 2010