kernel: ALSA: control: out-of-bounds access in get_ctl_id_hash()
Published Sep 13, 2022
7.8
HIGHCVSS 3.1
EPSS 0.25%
Description
An out-of-bounds access issue was found in the Linux kernel sound subsystem. It could occur when the 'id->name' provided by the user did not end with '\0'. A privileged local user could pass a specially crafted name through ioctl() interface and crash the system or potentially escalate their privileges on the system.
Affected products
- Vendor n/a Product Kernel Defaultn/a
- Version fixed in kernel 6.0-rc4StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| n/a | Kernel | n/a |
|
- 6.0
- 6.0
- 6.0
No data.
Red Hat Enterprise Linux 6
kernel
Not affected
Red Hat Enterprise Linux 7
kernel
Not affected
Red Hat Enterprise Linux 8
kernel
Not affected
Red Hat Enterprise Linux 9
kernel
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
Red Hat Enterprise Linux 6, 7, 8 and 9 are not affected by this flaw as they did not include support for faster lookup of control elements (upstream commit c27e1ef).
References (7)
- https://access.redhat.com/security/cve/CVE-2022-3170 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2125879 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-42592 Advisory
- https://github.com/torvalds/linux/commit/5934d9a0383619c14df91af8fd76261dc3de2f5f x_refsource_MISCPatchThird Party Advisory
- https://github.com/torvalds/linux/commit/6ab55ec0a938c7f943a4edba3d6514f775983887 x_refsource_MISCPatchThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2022-3170
- https://www.cve.org/CVERecord?id=CVE-2022-3170
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2022-3170 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2125879 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-42592 | Advisory | |
| https://github.com/torvalds/linux/commit/5934d9a0383619c14df91af8fd76261dc3de2f5f | x_refsource_MISCPatchThird Party Advisory | |
| https://github.com/torvalds/linux/commit/6ab55ec0a938c7f943a4edba3d6514f775983887 | x_refsource_MISCPatchThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2022-3170 | ||
| https://www.cve.org/CVERecord?id=CVE-2022-3170 |
Change history (0)
No recorded changes yet.