Back

HIGH

kernel: Use-after-free in snd_seq_ioctl_create_port()

Published Oct 16, 2017

Description

Race condition in the ALSA subsystem in the Linux kernel before 4.13.8 allows local users to cause a denial of service (use-after-free) or possibly have unspecified other impact via crafted /dev/snd/seq ioctl calls, related to sound/core/seq/seq_clientmgr.c and sound/core/seq/seq_ports.c.

Affected products

Remediation

Red Hat statement

This issue affects the Linux kernel packages as shipped with Red Hat Enterprise Linux 5,6, 7, realtime and MRG-2. Red Hat Enterprise Linux 5 has transitioned to Production phase 3. During the Production 3 Phase, Critical impact Security Advisories (RHSAs) and selected Urgent Priority Bug Fix Advisories (RHBAs) may be released as they become available. The official life cycle policy can be reviewed here: http://redhat.com/rhel/lifecycle Future Linux kernel updates for the respective releases may address this issue.

Red Hat mitigation

It is possible to prevent the affected code from being loaded by blacklisting the kernel module snd_seq. Instructions relating to how to blacklist a kernel module are shown here: https://access.redhat.com/solutions/41278 Alternatively a custom permission set can be created by udev, the correct permissions will depend on your use case. Please contact Red Hat customer support for creating a rule set that can minimize flaw exposure.

Metrics

References (26)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Oct 16, 2017
Updated Aug 5, 2024
Reserved Oct 11, 2017
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Oct 11, 2017