CVE-2016-9794
published 2016-12-28CVE-2016-9794: Race condition in the snd_pcm_period_elapsed function in sound/core/pcm_lib.c in the ALSA subsystem in the Linux kernel before 4.7 allows local users to cause…
PriorityP335high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.34%
26.1th percentile
Race condition in the snd_pcm_period_elapsed function in sound/core/pcm_lib.c in the ALSA subsystem in the Linux kernel before 4.7 allows local users to cause a denial of service (use-after-free) or possibly have unspecified other impact via a crafted SNDRV_PCM_TRIGGER_START command.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 4.7.2-1 (bookworm) | linux 4.7.2-1 (bookworm) |
| android | — | — | |
| linux | linux_kernel | < 3.2.85 | 3.2.85 |
| linux | linux_kernel | >= 0 < 4.7.2-1 | 4.7.2-1 |
| linux | linux_kernel | >= 0 < 4.7.2-1 | 4.7.2-1 |
| linux | linux_kernel | >= 0 < 4.7.2-1 | 4.7.2-1 |
| linux | linux_kernel | >= 0 < 4.7.2-1 | 4.7.2-1 |
| linux | linux_kernel | >= 0 < 3.13.0-107.154 | 3.13.0-107.154 |
| linux | linux_kernel | >= 0 < 4.4.0-59.80 | 4.4.0-59.80 |
| linux | linux_kernel | >= 3.11 < 3.12.69 | 3.12.69 |
| linux | linux_kernel | >= 3.13 < 3.16.40 | 3.16.40 |
| linux | linux_kernel | >= 3.17 < 3.18.52 | 3.18.52 |
| linux | linux_kernel | >= 3.19 < 4.4.37 | 4.4.37 |
| linux | linux_kernel | >= 3.3 < 3.10.105 | 3.10.105 |
| linux | linux_kernel | >= 4.5 < 4.7 | 4.7 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
vendor_ubuntu7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-4x89-4xjg-wjv4: Race condition in the snd_pcm_period_elapsed function in sound/core/pcm_lib
ghsa_unreviewed·2022-05-14
CVE-2016-9794 [HIGH] CWE-362 GHSA-4x89-4xjg-wjv4: Race condition in the snd_pcm_period_elapsed function in sound/core/pcm_lib
Race condition in the snd_pcm_period_elapsed function in sound/core/pcm_lib.c in the ALSA subsystem in the Linux kernel before 4.7 allows local users to cause a denial of service (use-after-free) or possibly have unspecified other impact via a crafted SNDRV_PCM_TRIGGER_START command.
OSV
linux vulnerabilities
osv·2017-01-11·CVSS 5.5
CVE-2016-9756 [MEDIUM] linux vulnerabilities
linux vulnerabilities
Dmitry Vyukov discovered that the KVM implementation in the Linux kernel
did not properly initialize the Code Segment (CS) in certain error cases. A
local attacker could use this to expose sensitive information (kernel
memory). (CVE-2016-9756)
Andrey Konovalov discovered that signed integer overflows existed in the
setsockopt() system call when handling the SO_SNDBUFFORCE and
SO_RCVBUFFORCE options. A local attacker with the CAP_NET_ADMIN capability
could use this to cause a denial of service (system crash or memory
corruption). (CVE-2016-9793)
Baozeng Ding discovered a race condition that could lead to a use-after-
free in the Advanced Linux Sound Architecture (ALSA) subsystem of the Linux
kernel. A local attacker could use this to cause a denial of service
(syste
OSV
linux-raspi2 vulnerabilities
osv·2017-01-11·CVSS 7.8
CVE-2016-9794 [HIGH] linux-raspi2 vulnerabilities
linux-raspi2 vulnerabilities
Baozeng Ding discovered a race condition that could lead to a use-after-
free in the Advanced Linux Sound Architecture (ALSA) subsystem of the Linux
kernel. A local attacker could use this to cause a denial of service
(system crash). (CVE-2016-9794)
Andrey Konovalov discovered that signed integer overflows existed in the
setsockopt() system call when handling the SO_SNDBUFFORCE and
SO_RCVBUFFORCE options. A local attacker with the CAP_NET_ADMIN capability
could use this to cause a denial of service (system crash or memory
corruption). (CVE-2016-9793)
OSV
linux vulnerabilities
osv·2017-01-11·CVSS 5.5
CVE-2016-9756 [MEDIUM] linux vulnerabilities
linux vulnerabilities
Dmitry Vyukov discovered that the KVM implementation in the Linux kernel
did not properly initialize the Code Segment (CS) in certain error cases. A
local attacker could use this to expose sensitive information (kernel
memory). (CVE-2016-9756)
Andrey Konovalov discovered that signed integer overflows existed in the
setsockopt() system call when handling the SO_SNDBUFFORCE and
SO_RCVBUFFORCE options. A local attacker with the CAP_NET_ADMIN capability
could use this to cause a denial of service (system crash or memory
corruption). (CVE-2016-9793)
Baozeng Ding discovered a race condition that could lead to a use-after-
free in the Advanced Linux Sound Architecture (ALSA) subsystem of the Linux
kernel. A local attacker could use this to cause a denial of service
(syste
OSV
linux-lts-xenial vulnerabilities
osv·2017-01-11·CVSS 5.5
CVE-2016-9756 [MEDIUM] linux-lts-xenial vulnerabilities
linux-lts-xenial vulnerabilities
USN-3169-1 fixed vulnerabilities in the Linux kernel for Ubuntu 16.04
LTS. This update provides the corresponding updates for the Linux
Hardware Enablement (HWE) kernel from Ubuntu 16.04 LTS for Ubuntu
14.04 LTS.
Dmitry Vyukov discovered that the KVM implementation in the Linux kernel
did not properly initialize the Code Segment (CS) in certain error cases. A
local attacker could use this to expose sensitive information (kernel
memory). (CVE-2016-9756)
Andrey Konovalov discovered that signed integer overflows existed in the
setsockopt() system call when handling the SO_SNDBUFFORCE and
SO_RCVBUFFORCE options. A local attacker with the CAP_NET_ADMIN capability
could use this to cause a denial of service (system crash or memory
corruption). (CVE-2016-9793)
OSV
linux-snapdragon vulnerabilities
osv·2017-01-11·CVSS 7.8
CVE-2016-9794 [HIGH] linux-snapdragon vulnerabilities
linux-snapdragon vulnerabilities
Baozeng Ding discovered a race condition that could lead to a use-after-
free in the Advanced Linux Sound Architecture (ALSA) subsystem of the Linux
kernel. A local attacker could use this to cause a denial of service
(system crash). (CVE-2016-9794)
Andrey Konovalov discovered that signed integer overflows existed in the
setsockopt() system call when handling the SO_SNDBUFFORCE and
SO_RCVBUFFORCE options. A local attacker with the CAP_NET_ADMIN capability
could use this to cause a denial of service (system crash or memory
corruption). (CVE-2016-9793)
OSV
CVE-2016-9794: Race condition in the snd_pcm_period_elapsed function in sound/core/pcm_lib
osv·2016-12-28·CVSS 7.8
CVE-2016-9794 [HIGH] CVE-2016-9794: Race condition in the snd_pcm_period_elapsed function in sound/core/pcm_lib
Race condition in the snd_pcm_period_elapsed function in sound/core/pcm_lib.c in the ALSA subsystem in the Linux kernel before 4.7 allows local users to cause a denial of service (use-after-free) or possibly have unspecified other impact via a crafted SNDRV_PCM_TRIGGER_START command.
Android
CVE-2016-9794: Android Security Bulletin 2017-05-01
CVE: CVE-2016-9794
Severity: CRITICAL
References: A-34068036
Upstream kernel
vendor_android·2017-05-01·CVSS 7.8
CVE-2016-9794 [HIGH] CVE-2016-9794: Android Security Bulletin 2017-05-01
CVE: CVE-2016-9794
Severity: CRITICAL
References: A-34068036
Upstream kernel
Android Security Bulletin 2017-05-01
CVE: CVE-2016-9794
Severity: CRITICAL
References: A-34068036
Upstream kernel
Ubuntu
Linux kernel (Qualcomm Snapdragon) vulnerabilities
vendor_ubuntu·2017-01-11·CVSS 7.8
CVE-2016-9793 [HIGH] Linux kernel (Qualcomm Snapdragon) vulnerabilities
Title: Linux kernel (Qualcomm Snapdragon) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Baozeng Ding discovered a race condition that could lead to a use-after-
free in the Advanced Linux Sound Architecture (ALSA) subsystem of the Linux
kernel. A local attacker could use this to cause a denial of service
(system crash). (CVE-2016-9794)
Andrey Konovalov discovered that signed integer overflows existed in the
setsockopt() system call when handling the SO_SNDBUFFORCE and
SO_RCVBUFFORCE options. A local attacker with the CAP_NET_ADMIN capability
could use this to cause a denial of service (system crash or memory
corruption). (CVE-2016-9793)
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTIO
Ubuntu
Linux kernel (Raspberry Pi 2) vulnerabilities
vendor_ubuntu·2017-01-11·CVSS 7.8
CVE-2016-9793 [HIGH] Linux kernel (Raspberry Pi 2) vulnerabilities
Title: Linux kernel (Raspberry Pi 2) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Baozeng Ding discovered a race condition that could lead to a use-after-
free in the Advanced Linux Sound Architecture (ALSA) subsystem of the Linux
kernel. A local attacker could use this to cause a denial of service
(system crash). (CVE-2016-9794)
Andrey Konovalov discovered that signed integer overflows existed in the
setsockopt() system call when handling the SO_SNDBUFFORCE and
SO_RCVBUFFORCE options. A local attacker with the CAP_NET_ADMIN capability
could use this to cause a denial of service (system crash or memory
corruption). (CVE-2016-9793)
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Du
Ubuntu
Linux kernel (OMAP4) vulnerabilities
vendor_ubuntu·2017-01-11·CVSS 5.5
CVE-2016-9756 [MEDIUM] Linux kernel (OMAP4) vulnerabilities
Title: Linux kernel (OMAP4) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Dmitry Vyukov discovered that the KVM implementation in the Linux kernel
did not properly initialize the Code Segment (CS) in certain error cases. A
local attacker could use this to expose sensitive information (kernel
memory). (CVE-2016-9756)
Baozeng Ding discovered a race condition that could lead to a use-after-
free in the Advanced Linux Sound Architecture (ALSA) subsystem of the Linux
kernel. A local attacker could use this to cause a denial of service
(system crash). (CVE-2016-9794)
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2017-01-11·CVSS 5.5
CVE-2016-9756 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
Dmitry Vyukov discovered that the KVM implementation in the Linux kernel
did not properly initialize the Code Segment (CS) in certain error cases. A
local attacker could use this to expose sensitive information (kernel
memory). (CVE-2016-9756)
Andrey Konovalov discovered that signed integer overflows existed in the
setsockopt() system call when handling the SO_SNDBUFFORCE and
SO_RCVBUFFORCE options. A local attacker with the CAP_NET_ADMIN capability
could use this to cause a denial of service (system crash or memory
corruption). (CVE-2016-9793)
Baozeng Ding discovered a race condition that could lead to a use-after-
free in the Advanced Linux Sound Architecture (ALSA) subsystem of the Linux
k
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2017-01-11·CVSS 5.5
CVE-2016-9756 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
Dmitry Vyukov discovered that the KVM implementation in the Linux kernel
did not properly initialize the Code Segment (CS) in certain error cases. A
local attacker could use this to expose sensitive information (kernel
memory). (CVE-2016-9756)
Andrey Konovalov discovered that signed integer overflows existed in the
setsockopt() system call when handling the SO_SNDBUFFORCE and
SO_RCVBUFFORCE options. A local attacker with the CAP_NET_ADMIN capability
could use this to cause a denial of service (system crash or memory
corruption). (CVE-2016-9793)
Baozeng Ding discovered a race condition that could lead to a use-after-
free in the Advanced Linux Sound Architecture (ALSA) subsystem of the Linux
k
Ubuntu
Linux kernel (Trusty HWE) vulnerabilities
vendor_ubuntu·2017-01-11·CVSS 5.5
CVE-2016-9756 [MEDIUM] Linux kernel (Trusty HWE) vulnerabilities
Title: Linux kernel (Trusty HWE) vulnerabilities
Summary: Several security issues were fixed in the kernel.
USN-3168-1 fixed vulnerabilities in the Linux kernel for Ubuntu 14.04
LTS. This update provides the corresponding updates for the Linux
Hardware Enablement (HWE) kernel from Ubuntu 14.04 LTS for Ubuntu
12.04 LTS.
Dmitry Vyukov discovered that the KVM implementation in the Linux kernel
did not properly initialize the Code Segment (CS) in certain error cases. A
local attacker could use this to expose sensitive information (kernel
memory). (CVE-2016-9756)
Andrey Konovalov discovered that signed integer overflows existed in the
setsockopt() system call when handling the SO_SNDBUFFORCE and
SO_RCVBUFFORCE options. A local attacker with the CAP_NET_ADMIN capability
could use this to cau
Ubuntu
Linux kernel (Xenial HWE) vulnerabilities
vendor_ubuntu·2017-01-11·CVSS 5.5
CVE-2016-9756 [MEDIUM] Linux kernel (Xenial HWE) vulnerabilities
Title: Linux kernel (Xenial HWE) vulnerabilities
Summary: Several security issues were fixed in the kernel.
USN-3169-1 fixed vulnerabilities in the Linux kernel for Ubuntu 16.04
LTS. This update provides the corresponding updates for the Linux
Hardware Enablement (HWE) kernel from Ubuntu 16.04 LTS for Ubuntu
14.04 LTS.
Dmitry Vyukov discovered that the KVM implementation in the Linux kernel
did not properly initialize the Code Segment (CS) in certain error cases. A
local attacker could use this to expose sensitive information (kernel
memory). (CVE-2016-9756)
Andrey Konovalov discovered that signed integer overflows existed in the
setsockopt() system call when handling the SO_SNDBUFFORCE and
SO_RCVBUFFORCE options. A local attacker with the CAP_NET_ADMIN capability
could use this to cau
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2017-01-11·CVSS 7.8
CVE-2016-9756 [HIGH] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
Dmitry Vyukov discovered that the KVM implementation in the Linux
kernel did not properly initialize the Code Segment (CS) in certain
error cases. A local attacker could use this to expose sensitive
information (kernel memory).
Baozeng Ding discovered a race condition that could lead to a use-after-
free in the Advanced Linux Sound Architecture (ALSA) subsystem of the Linux
kernel. A local attacker could use this to cause a denial of service
(system crash). (CVE-2016-9794)
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which re
Red Hat
kernel: ALSA: Use-after-free in kill_fasync
vendor_redhat·2016-04-14·CVSS 7.8
CVE-2016-9794 [HIGH] CWE-416 kernel: ALSA: Use-after-free in kill_fasync
kernel: ALSA: Use-after-free in kill_fasync
Race condition in the snd_pcm_period_elapsed function in sound/core/pcm_lib.c in the ALSA subsystem in the Linux kernel before 4.7 allows local users to cause a denial of service (use-after-free) or possibly have unspecified other impact via a crafted SNDRV_PCM_TRIGGER_START command.
A use-after-free vulnerability was found in ALSA pcm layer, which allows local users to cause a denial of service, memory corruption, or possibly other unspecified impact. Due to the nature of the flaw, privilege escalation cannot be fully ruled out, although we believe it is unlikely.
Statement: This issue affects the Linux kernel packages as shipped with Red Hat Enterprise Linux 5, 6. This has been rated as having Moderate security impact and is not currently pl
Debian
CVE-2016-9794: linux - Race condition in the snd_pcm_period_elapsed function in sound/core/pcm_lib.c in...
vendor_debian·2016·CVSS 7.8
CVE-2016-9794 [HIGH] CVE-2016-9794: linux - Race condition in the snd_pcm_period_elapsed function in sound/core/pcm_lib.c in...
Race condition in the snd_pcm_period_elapsed function in sound/core/pcm_lib.c in the ALSA subsystem in the Linux kernel before 4.7 allows local users to cause a denial of service (use-after-free) or possibly have unspecified other impact via a crafted SNDRV_PCM_TRIGGER_START command.
Scope: local
bookworm: resolved (fixed in 4.7.2-1)
bullseye: resolved (fixed in 4.7.2-1)
forky: resolved (fixed in 4.7.2-1)
sid: resolved (fixed in 4.7.2-1)
trixie: resolved (fixed in 4.7.2-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-9794 kernel: ALSA: Use-after-free in kill_fasync
bugzilla·2016-12-05·CVSS 7.8
CVE-2016-9794 [HIGH] CVE-2016-9794 kernel: ALSA: Use-after-free in kill_fasync
CVE-2016-9794 kernel: ALSA: Use-after-free in kill_fasync
A use-after-free vulnerability was found in ALSA pcm layer, which allows local users to cause a denial of service, memory corruption or possibly other unspecified impact. Due to the nature of the flaw, privilege escalation cannot be fully ruled out, although we believe it is unlikely.
References:
https://patchwork.kernel.org/patch/8752621/
Upstream patch:
https://github.com/torvalds/linux/commit/3aa02cb664c5fb1042958c8d1aa8c35055a2ebc4
CVE-ID request+assign:
http://seclists.org/oss-sec/2016/q4/575
Discussion:
Statement:
This issue affects the Linux kernel packages as shipped with Red Hat Enterprise Linux 5, 6. This has been rated as having Moderate security impact and is not currently planned to be addressed in future upda
arXiv
Understanding Concurrency Vulnerabilities in Linux Kernel
arxiv_fulltext·2022-12-11
Understanding Concurrency Vulnerabilities in Linux Kernel
Understanding Concurrency Vulnerabilities in Linux Kernel
Zunchen Huang
University of Southern California
Los Angeles, CA
USA
Shengjian Guo
Baidu Security
Sunnyvale, CA
USA
Meng Wu
Virginia Tech
Blacksburg, VA
USA
Chao Wang
University of Southern California
Los Angeles, CA
USA
## Abstract
While there is a large body of work on analyzing concurrency related
software bugs and developing techniques for detecting and patching
them, little attention has been given to concurrency related security
vulnerabilities. The two are different in that not all bugs are
vulnerabilities: for a bug to be exploitable, there needs be a way for
attackers to trigger its execution and cause damage, e.g., by
revealing sensitive data or running malicious code.
To fill the gap, we conduct the first empiri
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=3aa02cb664c5fb1042958c8d1aa8c35055a2ebc4http://lists.opensuse.org/opensuse-security-announce/2016-12/msg00057.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-12/msg00062.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-12/msg00072.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-12/msg00075.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-12/msg00081.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-12/msg00088.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-12/msg00091.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2574.htmlhttp://www.openwall.com/lists/oss-security/2016/12/03/2http://www.securityfocus.com/bid/94654https://bugzilla.redhat.com/show_bug.cgi?id=1401494https://github.com/torvalds/linux/commit/3aa02cb664c5fb1042958c8d1aa8c35055a2ebc4https://patchwork.kernel.org/patch/8752621/https://source.android.com/security/bulletin/2017-05-01http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=3aa02cb664c5fb1042958c8d1aa8c35055a2ebc4http://lists.opensuse.org/opensuse-security-announce/2016-12/msg00057.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-12/msg00062.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-12/msg00072.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-12/msg00075.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-12/msg00081.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-12/msg00088.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-12/msg00091.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2574.htmlhttp://www.openwall.com/lists/oss-security/2016/12/03/2http://www.securityfocus.com/bid/94654https://bugzilla.redhat.com/show_bug.cgi?id=1401494https://github.com/torvalds/linux/commit/3aa02cb664c5fb1042958c8d1aa8c35055a2ebc4https://patchwork.kernel.org/patch/8752621/https://source.android.com/security/bulletin/2017-05-01
2016-12-28
Published