cbcvebase.
CVE-2016-4578
published 2016-05-23

CVE-2016-4578: sound/core/timer.c in the Linux kernel through 4.6 does not initialize certain r1 data structures, which allows local users to obtain sensitive information…

medium5.5CVSS 3.0
AVLACLPRLUINSUCHINAN
EXPLOIT
sound/core/timer.c in the Linux kernel through 4.6 does not initialize certain r1 data structures, which allows local users to obtain sensitive information from kernel stack memory via crafted use of the ALSA timer interface, related to the (1) snd_timer_user_ccallback and (2) snd_timer_user_tinterrupt functions.

Affected

28 ranges· showing 25
VendorProductVersion rangeFixed in
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debiandebian_linux
debianlinux< linux 4.5.5-1 (bookworm)linux 4.5.5-1 (bookworm)
googleandroid
linuxlinux_kernel<= 4.6
linuxlinux_kernel>= 0 < 4.5.5-14.5.5-1
linuxlinux_kernel>= 0 < 4.5.5-14.5.5-1
linuxlinux_kernel>= 0 < 4.5.5-14.5.5-1
linuxlinux_kernel>= 0 < 4.5.5-14.5.5-1
linuxlinux_kernel>= 0 < 3.13.0-91.1383.13.0-91.138
linuxlinux_kernel>= 0 < 4.4.0-28.474.4.0-28.47
opensuseleap
opensuseopensuse
redhatenterprise_linux_desktop
redhatenterprise_linux_server
redhatenterprise_linux_server_aus
redhatenterprise_linux_server_aus
redhatenterprise_linux_server_aus
redhatenterprise_linux_server_eus
redhatenterprise_linux_server_eus
redhatenterprise_linux_server_eus
redhatenterprise_linux_server_eus

CVSS provenance

nvdv3.05.5MEDIUMCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
osv6.2MEDIUM