Back

HIGH

kernel: MIDI driver race condition leads to a double-free

Published Aug 21, 2018

Description

It was found that the raw midi kernel driver does not protect against concurrent access which leads to a double realloc (double free) in snd_rawmidi_input_params() and snd_rawmidi_output_status() which are part of snd_rawmidi_ioctl() handler in rawmidi.c file. A malicious local attacker could possibly use this for privilege escalation.

Affected products

Remediation

Red Hat statement

This flaw affects all current shipping releases of Red Hat Enterprise Linux. This flaw requires real or emulated midi hardware available in the system. Fixes will be delivered when available.

Metrics

References (23)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Aug 21, 2018
Updated Jul 7, 2026
Reserved May 9, 2018
NVD
Status Modified
Modified Jul 7, 2026
Red Hat
Severity Important
Public date Aug 21, 2018