CVE-2016-2546
published 2016-04-27CVE-2016-2546: sound/core/timer.c in the Linux kernel before 4.4.1 uses an incorrect type of mutex, which allows local users to cause a denial of service (race condition…
PriorityP417medium5.1CVSS 3.0
AVLACHPRNUINSUCNINAH
EPSS
0.34%
26.5th percentile
sound/core/timer.c in the Linux kernel before 4.4.1 uses an incorrect type of mutex, which allows local users to cause a denial of service (race condition, use-after-free, and system crash) via a crafted ioctl call.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 4.4.2-1 (bookworm) | linux 4.4.2-1 (bookworm) |
| android | — | — | |
| linux | linux_kernel | <= 4.4 | — |
| linux | linux_kernel | >= 0 < 4.4.2-1 | 4.4.2-1 |
| linux | linux_kernel | >= 0 < 4.4.2-1 | 4.4.2-1 |
| linux | linux_kernel | >= 0 < 4.4.2-1 | 4.4.2-1 |
| linux | linux_kernel | >= 0 < 4.4.2-1 | 4.4.2-1 |
| linux | linux_kernel | >= 0 < 3.13.0-83.127 | 3.13.0-83.127 |
CVSS provenance
nvdv3.05.1MEDIUMCVSS:3.0/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.04.7MEDIUMAV:L/AC:M/Au:N/C:N/I:N/A:C
osv6.2MEDIUM
vendor_ubuntu6.2MEDIUM
vendor_debian5.1MEDIUM
vendor_redhat5.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-qr7g-w49q-3pg6: sound/core/timer
ghsa_unreviewed·2022-05-17
CVE-2016-2546 [MEDIUM] CWE-362 GHSA-qr7g-w49q-3pg6: sound/core/timer
sound/core/timer.c in the Linux kernel before 4.4.1 uses an incorrect type of mutex, which allows local users to cause a denial of service (race condition, use-after-free, and system crash) via a crafted ioctl call.
OSV
CVE-2016-2546: sound/core/timer
osv·2016-04-27·CVSS 5.1
CVE-2016-2546 [MEDIUM] CVE-2016-2546: sound/core/timer
sound/core/timer.c in the Linux kernel before 4.4.1 uses an incorrect type of mutex, which allows local users to cause a denial of service (race condition, use-after-free, and system crash) via a crafted ioctl call.
OSV
linux-lts-wily vulnerabilities
osv·2016-03-14·CVSS 4.6
CVE-2016-3134 [MEDIUM] linux-lts-wily vulnerabilities
linux-lts-wily vulnerabilities
Ben Hawkes discovered that the Linux netfilter implementation did not
correctly perform validation when handling IPT_SO_SET_REPLACE events. A
local unprivileged attacker could use this to cause a denial of service
(system crash) or possibly execute arbitrary code with administrative
privileges. (CVE-2016-3134)
Ben Hawkes discovered an integer overflow in the Linux netfilter
implementation. On systems running 32 bit kernels, a local unprivileged
attacker could use this to cause a denial of service (system crash) or
possibly execute arbitrary code with administrative privileges.
(CVE-2016-3135)
Ralf Spenneberg discovered that the USB driver for Clie devices in the
Linux kernel did not properly validate the endpoints reported by the
device. An attacker with p
OSV
linux-lts-vivid vulnerabilities
osv·2016-03-14·CVSS 6.2
CVE-2016-3134 [MEDIUM] linux-lts-vivid vulnerabilities
linux-lts-vivid vulnerabilities
Ben Hawkes discovered that the Linux netfilter implementation did not
correctly perform validation when handling IPT_SO_SET_REPLACE events. A
local unprivileged attacker could use this to cause a denial of service
(system crash) or possibly execute arbitrary code with administrative
privileges. (CVE-2016-3134)
It was discovered that the Linux kernel did not properly enforce rlimits
for file descriptors sent over UNIX domain sockets. A local attacker could
use this to cause a denial of service. (CVE-2013-4312)
Ralf Spenneberg discovered that the USB driver for Clie devices in the
Linux kernel did not properly validate the endpoints reported by the
device. An attacker with physical access could cause a denial of service
(system crash). (CVE-2015-7566)
Ralf
OSV
linux-lts-utopic vulnerabilities
osv·2016-03-14·CVSS 6.2
CVE-2016-3134 [MEDIUM] linux-lts-utopic vulnerabilities
linux-lts-utopic vulnerabilities
Ben Hawkes discovered that the Linux netfilter implementation did not
correctly perform validation when handling IPT_SO_SET_REPLACE events. A
local unprivileged attacker could use this to cause a denial of service
(system crash) or possibly execute arbitrary code with administrative
privileges. (CVE-2016-3134)
It was discovered that the Linux kernel did not properly enforce rlimits
for file descriptors sent over UNIX domain sockets. A local attacker could
use this to cause a denial of service. (CVE-2013-4312)
It was discovered that a race condition existed when handling heartbeat-
timeout events in the SCTP implementation of the Linux kernel. A remote
attacker could use this to cause a denial of service. (CVE-2015-8767)
Andy Lutomirski discovered a race
OSV
linux vulnerabilities
osv·2016-03-14·CVSS 6.2
CVE-2016-3134 [MEDIUM] linux vulnerabilities
linux vulnerabilities
Ben Hawkes discovered that the Linux netfilter implementation did not
correctly perform validation when handling IPT_SO_SET_REPLACE events. A
local unprivileged attacker could use this to cause a denial of service
(system crash) or possibly execute arbitrary code with administrative
privileges. (CVE-2016-3134)
It was discovered that the Linux kernel did not properly enforce rlimits
for file descriptors sent over UNIX domain sockets. A local attacker could
use this to cause a denial of service. (CVE-2013-4312)
Ralf Spenneberg discovered that the USB driver for Clie devices in the
Linux kernel did not properly validate the endpoints reported by the
device. An attacker with physical access could cause a denial of service
(system crash). (CVE-2015-7566)
Ralf Spenneber
Android
CVE-2016-2546: Android Security Bulletin 2016-08-01
CVE: CVE-2016-2546
Severity: HIGH
References: A-28694392
Upstream kernel
vendor_android·2016-08-01·CVSS 5.1
CVE-2016-2546 [MEDIUM] CVE-2016-2546: Android Security Bulletin 2016-08-01
CVE: CVE-2016-2546
Severity: HIGH
References: A-28694392
Upstream kernel
Android Security Bulletin 2016-08-01
CVE: CVE-2016-2546
Severity: HIGH
References: A-28694392
Upstream kernel
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2016-05-09·CVSS 6.2
CVE-2013-4312 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
It was discovered that the Linux kernel did not properly enforce rlimits
for file descriptors sent over UNIX domain sockets. A local attacker could
use this to cause a denial of service. (CVE-2013-4312)
Ralf Spenneberg discovered that the Aiptek Tablet USB device driver in the
Linux kernel did not properly validate the endpoints reported by the
device. An attacker with physical access could cause a denial of service
(system crash). (CVE-2015-7515)
Ralf Spenneberg discovered that the USB driver for Clie devices in the
Linux kernel did not properly validate the endpoints reported by the
device. An attacker with physical access could cause a denial of service
(system crash). (CVE-2015-7566)
Ral
Ubuntu
Linux kernel (OMAP4) vulnerabilities
vendor_ubuntu·2016-05-09·CVSS 6.2
CVE-2013-4312 [MEDIUM] Linux kernel (OMAP4) vulnerabilities
Title: Linux kernel (OMAP4) vulnerabilities
Summary: Several security issues were fixed in the kernel.
It was discovered that the Linux kernel did not properly enforce rlimits
for file descriptors sent over UNIX domain sockets. A local attacker could
use this to cause a denial of service. (CVE-2013-4312)
Ralf Spenneberg discovered that the Aiptek Tablet USB device driver in the
Linux kernel did not properly validate the endpoints reported by the
device. An attacker with physical access could cause a denial of service
(system crash). (CVE-2015-7515)
Ralf Spenneberg discovered that the USB driver for Clie devices in the
Linux kernel did not properly validate the endpoints reported by the
device. An attacker with physical access could cause a denial of service
(system crash). (CVE-2015-75
Ubuntu
Linux kernel (Raspberry Pi 2) vulnerabilities
vendor_ubuntu·2016-03-16·CVSS 4.6
CVE-2015-7566 [MEDIUM] Linux kernel (Raspberry Pi 2) vulnerabilities
Title: Linux kernel (Raspberry Pi 2) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Ben Hawkes discovered that the Linux netfilter implementation did not
correctly perform validation when handling IPT_SO_SET_REPLACE events. A
local unprivileged attacker could use this to cause a denial of service
(system crash) or possibly execute arbitrary code with administrative
privileges. (CVE-2016-3134)
Ben Hawkes discovered an integer overflow in the Linux netfilter
implementation. On systems running 32 bit kernels, a local unprivileged
attacker could use this to cause a denial of service (system crash) or
possibly execute arbitrary code with administrative privileges.
(CVE-2016-3135)
Ralf Spenneberg discovered that the USB driver for Clie devices in the
Linux kernel
Ubuntu
Linux kernel (Wily HWE) vulnerabilities
vendor_ubuntu·2016-03-14·CVSS 4.6
CVE-2015-7566 [MEDIUM] Linux kernel (Wily HWE) vulnerabilities
Title: Linux kernel (Wily HWE) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Ben Hawkes discovered that the Linux netfilter implementation did not
correctly perform validation when handling IPT_SO_SET_REPLACE events. A
local unprivileged attacker could use this to cause a denial of service
(system crash) or possibly execute arbitrary code with administrative
privileges. (CVE-2016-3134)
Ben Hawkes discovered an integer overflow in the Linux netfilter
implementation. On systems running 32 bit kernels, a local unprivileged
attacker could use this to cause a denial of service (system crash) or
possibly execute arbitrary code with administrative privileges.
(CVE-2016-3135)
Ralf Spenneberg discovered that the USB driver for Clie devices in the
Linux kernel did no
Ubuntu
Linux kernel (Trusty HWE) vulnerabilities
vendor_ubuntu·2016-03-14·CVSS 6.2
CVE-2013-4312 [MEDIUM] Linux kernel (Trusty HWE) vulnerabilities
Title: Linux kernel (Trusty HWE) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Ben Hawkes discovered that the Linux netfilter implementation did not
correctly perform validation when handling IPT_SO_SET_REPLACE events. A
local unprivileged attacker could use this to cause a denial of service
(system crash) or possibly execute arbitrary code with administrative
privileges. (CVE-2016-3134)
It was discovered that the Linux kernel did not properly enforce rlimits
for file descriptors sent over UNIX domain sockets. A local attacker could
use this to cause a denial of service. (CVE-2013-4312)
Ralf Spenneberg discovered that the USB driver for Clie devices in the
Linux kernel did not properly validate the endpoints reported by the
device. An attacker with physical
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2016-03-14·CVSS 4.6
CVE-2015-7566 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
Ben Hawkes discovered that the Linux netfilter implementation did not
correctly perform validation when handling IPT_SO_SET_REPLACE events. A
local unprivileged attacker could use this to cause a denial of service
(system crash) or possibly execute arbitrary code with administrative
privileges. (CVE-2016-3134)
Ben Hawkes discovered an integer overflow in the Linux netfilter
implementation. On systems running 32 bit kernels, a local unprivileged
attacker could use this to cause a denial of service (system crash) or
possibly execute arbitrary code with administrative privileges.
(CVE-2016-3135)
Ralf Spenneberg discovered that the USB driver for Clie devices in the
Linux kernel did not properly
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2016-03-14·CVSS 6.2
CVE-2013-4312 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
Ben Hawkes discovered that the Linux netfilter implementation did not
correctly perform validation when handling IPT_SO_SET_REPLACE events. A
local unprivileged attacker could use this to cause a denial of service
(system crash) or possibly execute arbitrary code with administrative
privileges. (CVE-2016-3134)
It was discovered that the Linux kernel did not properly enforce rlimits
for file descriptors sent over UNIX domain sockets. A local attacker could
use this to cause a denial of service. (CVE-2013-4312)
Ralf Spenneberg discovered that the USB driver for Clie devices in the
Linux kernel did not properly validate the endpoints reported by the
device. An attacker with physical access could
Ubuntu
Linux kernel (Vivid HWE) vulnerabilities
vendor_ubuntu·2016-03-14·CVSS 6.2
CVE-2013-4312 [MEDIUM] Linux kernel (Vivid HWE) vulnerabilities
Title: Linux kernel (Vivid HWE) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Ben Hawkes discovered that the Linux netfilter implementation did not
correctly perform validation when handling IPT_SO_SET_REPLACE events. A
local unprivileged attacker could use this to cause a denial of service
(system crash) or possibly execute arbitrary code with administrative
privileges. (CVE-2016-3134)
It was discovered that the Linux kernel did not properly enforce rlimits
for file descriptors sent over UNIX domain sockets. A local attacker could
use this to cause a denial of service. (CVE-2013-4312)
Ralf Spenneberg discovered that the USB driver for Clie devices in the
Linux kernel did not properly validate the endpoints reported by the
device. An attacker with physical
Ubuntu
Linux kernel (Utopic HWE) vulnerabilities
vendor_ubuntu·2016-03-14·CVSS 6.2
CVE-2013-4312 [MEDIUM] Linux kernel (Utopic HWE) vulnerabilities
Title: Linux kernel (Utopic HWE) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Ben Hawkes discovered that the Linux netfilter implementation did not
correctly perform validation when handling IPT_SO_SET_REPLACE events. A
local unprivileged attacker could use this to cause a denial of service
(system crash) or possibly execute arbitrary code with administrative
privileges. (CVE-2016-3134)
It was discovered that the Linux kernel did not properly enforce rlimits
for file descriptors sent over UNIX domain sockets. A local attacker could
use this to cause a denial of service. (CVE-2013-4312)
It was discovered that a race condition existed when handling heartbeat-
timeout events in the SCTP implementation of the Linux kernel. A remote
attacker could use this to c
Red Hat
kernel: sound: GPF in snd_timer_user_params
vendor_redhat·2016-01-19·CVSS 5.1
CVE-2016-2546 [MEDIUM] CWE-416 kernel: sound: GPF in snd_timer_user_params
kernel: sound: GPF in snd_timer_user_params
sound/core/timer.c in the Linux kernel before 4.4.1 uses an incorrect type of mutex, which allows local users to cause a denial of service (race condition, use-after-free, and system crash) via a crafted ioctl call.
Statement: This issue affects the Linux kernel packages as shipped with Red Hat Enterprise Linux 5, 6, 7 and MRG-2. This has been rated as having Moderate security impact and is not currently planned to be addressed in future updates. For additional information, refer to the Red Hat Enterprise Linux Life Cycle: https://access.redhat.com/support/policy/updates/errata/.
Package: kernel (Red Hat Enterprise Linux 5) - Will not fix
Package: kernel (Red Hat Enterprise Linux 6) - Will not fix
Package: kernel (Red Hat Enterprise Linux 7)
Debian
CVE-2016-2546: linux - sound/core/timer.c in the Linux kernel before 4.4.1 uses an incorrect type of mu...
vendor_debian·2016·CVSS 5.1
CVE-2016-2546 [MEDIUM] CVE-2016-2546: linux - sound/core/timer.c in the Linux kernel before 4.4.1 uses an incorrect type of mu...
sound/core/timer.c in the Linux kernel before 4.4.1 uses an incorrect type of mutex, which allows local users to cause a denial of service (race condition, use-after-free, and system crash) via a crafted ioctl call.
Scope: local
bookworm: resolved (fixed in 4.4.2-1)
bullseye: resolved (fixed in 4.4.2-1)
forky: resolved (fixed in 4.4.2-1)
sid: resolved (fixed in 4.4.2-1)
trixie: resolved (fixed in 4.4.2-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-3658 libtiff: out-of-bounds read in the TIFFWriteDirectoryTagLongLong8Array function
bugzilla·2016-04-12·CVSS 6.5
CVE-2016-3658 [MEDIUM] CVE-2016-3658 libtiff: out-of-bounds read in the TIFFWriteDirectoryTagLongLong8Array function
CVE-2016-3658 libtiff: out-of-bounds read in the TIFFWriteDirectoryTagLongLong8Array function
A vulnerability was found in the libtiff library. Using a tiffset command on a maliciously crafted image could result in a denial-of-service.
Vulnerable code:
/libtiff/tif_dirwrite.c: 1625
1623 for (q=p, ma=value, mb=0; mb0xFFFFFFFF)
1626 {
1627 TIFFErrorExt(tif->tif_clientdata,module,
1628 "Attempt to write value larger than 0xFFFFFFFF in Classic TIFF file.");
1629 _TIFFfree(p);
1630 return(0);
1631 }
1632 *q= (uint32)(*ma);
1633 }
References:
http://www.openwall.com/lists/oss-security/2016/04/08/12
Discussion:
External References:
http://bugzilla.maptools.org/show_bug.cgi?id=2546
---
*** This bug has been marked as a duplicate of bug 1185805 ***
---
Statement:
This flaw was found to
Bugzilla
CVE-2016-2546 kernel: sound: GPF in snd_timer_user_params
bugzilla·2016-02-24·CVSS 5.1
CVE-2016-2546 [MEDIUM] CVE-2016-2546 kernel: sound: GPF in snd_timer_user_params
CVE-2016-2546 kernel: sound: GPF in snd_timer_user_params
ALSA timer ioctls have an open race and this may lead to a use-after-free of timer instance object. A simplistic fix is to make each ioctl exclusive. We have already tread_sem for controlling the tread, and extend this as a global mutex to be applied to each ioctl.
Upstream patch:
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=af368027a49a751d6ff4ee9e3f9961f35bb4fede
CVE-ID request and assignment:
http://seclists.org/oss-sec/2016/q1/133
http://seclists.org/oss-sec/2016/q1/410
Discussion:
This was fixed in 4.3.5 with
commit 7066da22b1eb40e955f9dfe57022816fae53d3cf
Author: Takashi Iwai
Date: Wed Jan 13 17:48:01 2016 +0100
ALSA: timer: Fix race among timer ioctls
commit af368027a49a751d6ff4ee9e3f99
Bugzilla
CVE-2016-2543 CVE-2016-2544 CVE-2016-2545 CVE-2016-2546 CVE-2016-2547 CVE-2016-2548 CVE-2016-2549 kernel: sound: multiple security vulnerabilities [fedora-all]
bugzilla·2016-02-24·CVSS 6.2
CVE-2016-2543 [MEDIUM] CVE-2016-2543 CVE-2016-2544 CVE-2016-2545 CVE-2016-2546 CVE-2016-2547 CVE-2016-2548 CVE-2016-2549 kernel: sound: multiple security vulnerabilities [fedora-all]
CVE-2016-2543 CVE-2016-2544 CVE-2016-2545 CVE-2016-2546 CVE-2016-2547 CVE-2016-2548 CVE-2016-2549 kernel: sound: multiple security vulnerabilities [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and th
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=af368027a49a751d6ff4ee9e3f9961f35bb4fedehttp://lists.opensuse.org/opensuse-security-announce/2016-03/msg00094.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-04/msg00045.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-08/msg00038.htmlhttp://www.debian.org/security/2016/dsa-3503http://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.4.1http://www.openwall.com/lists/oss-security/2016/01/19/1http://www.securityfocus.com/bid/83384http://www.securitytracker.com/id/1035301http://www.ubuntu.com/usn/USN-2929-1http://www.ubuntu.com/usn/USN-2929-2http://www.ubuntu.com/usn/USN-2930-1http://www.ubuntu.com/usn/USN-2930-2http://www.ubuntu.com/usn/USN-2930-3http://www.ubuntu.com/usn/USN-2931-1http://www.ubuntu.com/usn/USN-2932-1http://www.ubuntu.com/usn/USN-2967-1http://www.ubuntu.com/usn/USN-2967-2https://bugzilla.redhat.com/show_bug.cgi?id=1311564https://github.com/torvalds/linux/commit/af368027a49a751d6ff4ee9e3f9961f35bb4fedehttp://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=af368027a49a751d6ff4ee9e3f9961f35bb4fedehttp://lists.opensuse.org/opensuse-security-announce/2016-03/msg00094.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-04/msg00045.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-08/msg00038.htmlhttp://www.debian.org/security/2016/dsa-3503http://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.4.1http://www.openwall.com/lists/oss-security/2016/01/19/1http://www.securityfocus.com/bid/83384http://www.securitytracker.com/id/1035301http://www.ubuntu.com/usn/USN-2929-1http://www.ubuntu.com/usn/USN-2929-2http://www.ubuntu.com/usn/USN-2930-1http://www.ubuntu.com/usn/USN-2930-2http://www.ubuntu.com/usn/USN-2930-3http://www.ubuntu.com/usn/USN-2931-1http://www.ubuntu.com/usn/USN-2932-1http://www.ubuntu.com/usn/USN-2967-1http://www.ubuntu.com/usn/USN-2967-2https://bugzilla.redhat.com/show_bug.cgi?id=1311564https://github.com/torvalds/linux/commit/af368027a49a751d6ff4ee9e3f9961f35bb4fede
2016-04-27
Published