Back

HIGH

kernel: ALSA: control: out-of-bounds access in get_ctl_id_hash()

Published Sep 13, 2022

Description

An out-of-bounds access issue was found in the Linux kernel sound subsystem. It could occur when the 'id->name' provided by the user did not end with '\0'. A privileged local user could pass a specially crafted name through ioctl() interface and crash the system or potentially escalate their privileges on the system.

Affected products

Remediation

Red Hat statement

Red Hat Enterprise Linux 6, 7, 8 and 9 are not affected by this flaw as they did not include support for faster lookup of control elements (upstream commit c27e1ef).

References (7)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Sep 13, 2022
Updated Aug 3, 2024
Reserved Sep 9, 2022
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Aug 24, 2022
ENISA EUVD
Assigner redhat
Published Sep 13, 2022
Updated Aug 3, 2024
Exploited since n/a
EUVD-2022-42592