CVE-2016-4569
Severity
5.5MEDIUM
EPSS
0.3%
top 43.75%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMay 23
Latest updateMay 14
Description
The snd_timer_user_params function in sound/core/timer.c in the Linux kernel through 4.6 does not initialize a certain data structure, which allows local users to obtain sensitive information from kernel stack memory via crafted use of the ALSA timer interface.
CVSS vector
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 1.8 | Impact: 3.6
Affected Packages10 packages
Also affects: Ubuntu Linux 12.04, 14.04, 15.10, 16.04
🔴Vulnerability Details
3📋Vendor Advisories
14Android▶
CVE-2016-4569: Android Security Bulletin 2016-08-01
CVE: CVE-2016-4569
Severity: MEDIUM
References: A-28980557
Upstream kernel↗2016-08-01