CVE-2014-4653 — Use After Free in Kernel
Severity
4.6MEDIUMNVD
EPSS
0.1%
top 79.49%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJul 3
Latest updateMay 13
Description
sound/core/control.c in the ALSA control implementation in the Linux kernel before 3.15.2 does not ensure possession of a read/write lock, which allows local users to cause a denial of service (use-after-free) and obtain sensitive information from kernel memory by leveraging /dev/snd/controlCX access.
CVSS vector
AV:L/AC:L/C:P/I:P/A:PExploitability: 3.9 | Impact: 6.4
Affected Packages3 packages
Also affects: Ubuntu Linux 12.04
Patches
🔴Vulnerability Details
3📋Vendor Advisories
8💬Community
1Bugzilla
▶