CVE-2016-4569

Severity
5.5MEDIUM
EPSS
0.3%
top 43.75%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 23
Latest updateMay 14

Description

The snd_timer_user_params function in sound/core/timer.c in the Linux kernel through 4.6 does not initialize a certain data structure, which allows local users to obtain sensitive information from kernel stack memory via crafted use of the ALSA timer interface.

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 1.8 | Impact: 3.6

Affected Packages10 packages

Also affects: Ubuntu Linux 12.04, 14.04, 15.10, 16.04

🔴Vulnerability Details

3
GHSA
GHSA-8p5x-59f8-f4c8: The snd_timer_user_params function in sound/core/timer2022-05-14
OSV
CVE-2016-4569: The snd_timer_user_params function in sound/core/timer2016-05-23
CVEList
CVE-2016-4569: The snd_timer_user_params function in sound/core/timer2016-05-23

📋Vendor Advisories

14
Android
CVE-2016-4569: Android Security Bulletin 2016-08-01 CVE: CVE-2016-4569 Severity: MEDIUM References: A-28980557 Upstream kernel2016-08-01
Ubuntu
Linux kernel (Wily HWE) vulnerabilities2016-06-27
Ubuntu
Linux kernel vulnerabilities2016-06-27
Ubuntu
Linux kernel (Vivid HWE) vulnerabilities2016-06-27
Ubuntu
Linux kernel (OMAP4) vulnerabilities2016-06-27

💬Community

2
Bugzilla
CVE-2016-4569 kernel: Information leak in Linux sound module in timer.c2016-05-10
Bugzilla
CVE-2016-4569 kernel: Information leak in Linux sound module in timer.c [fedora-all]2016-05-10