CVE-2010-3442Integer Overflow or Wraparound in Kernel

Severity
4.7MEDIUMNVD
EPSS
0.2%
top 60.82%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 4
Latest updateMay 13

Description

Multiple integer overflows in the snd_ctl_new function in sound/core/control.c in the Linux kernel before 2.6.36-rc5-next-20100929 allow local users to cause a denial of service (heap memory corruption) or possibly have unspecified other impact via a crafted (1) SNDRV_CTL_IOCTL_ELEM_ADD or (2) SNDRV_CTL_IOCTL_ELEM_REPLACE ioctl call.

CVSS vector

AV:L/AC:M/C:N/I:N/A:CExploitability: 3.4 | Impact: 6.9

Affected Packages6 packages

Also affects: Debian Linux 5.0, Ubuntu Linux 10.04, 10.10, 6.06, 8.04, 9.04, 9.10, Fedora 13

Patches

🔴Vulnerability Details

2
GHSA
GHSA-3x4p-qf5f-hhw9: Multiple integer overflows in the snd_ctl_new function in sound/core/control2022-05-13
CVEList
CVE-2010-3442: Multiple integer overflows in the snd_ctl_new function in sound/core/control2010-10-04

📋Vendor Advisories

6
Ubuntu
Linux Kernel vulnerabilities (Marvell Dove)2011-03-25
Ubuntu
Linux kernel vulnerabilities2011-03-03
Ubuntu
Linux kernel vulnerabilities2011-02-28
Ubuntu
Linux kernel vulnerabilities2011-02-25
Ubuntu
Linux kernel vulnerabilities2010-10-19

💬Community

1
Bugzilla
CVE-2010-3442 kernel: prevent heap corruption in snd_ctl_new()2010-09-29
CVE-2010-3442 — Integer Overflow or Wraparound | cvebase