CVE-2017-0861Use After Free in INC Android

CWE-416Use After Free23 documents10 sources
Severity
7.8HIGHNVD
EPSS
0.1%
top 75.40%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 16
Latest updateMay 13

Description

Use-after-free vulnerability in the snd_pcm_info function in the ALSA subsystem in the Linux kernel allows attackers to gain privileges via unspecified vectors.

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages3 packages

Debianlinux/linux_kernel< 4.13.4-1+3
Ubuntulinux/linux_kernel< 3.13.0-142.191+1
CVEListV5google_inc/androidAndroid kernel

Patches

🔴Vulnerability Details

9
GHSA
GHSA-pxhw-6q9j-34m8: Use-after-free vulnerability in the snd_pcm_info function in the ALSA subsystem in the Linux kernel allows attackers to gain privileges via unspecifie2022-05-13
OSV
linux-azure vulnerabilities2018-04-24
OSV
linux-lts-xenial, linux-aws vulnerabilities2018-04-05
OSV
linux, linux-aws, linux-kvm, linux-raspi2, linux-snapdragon vulnerabilities2018-04-04
OSV
linux-hwe, linux-gcp, linux-oem vulnerabilities2018-04-03

📋Vendor Advisories

11
Oracle
Oracle Oracle Communications Applications Risk Matrix: Kernel — CVE-2017-08612020-07-15
Ubuntu
Linux kernel (Azure) vulnerabilities2018-04-24
Ubuntu
Linux kernel (Xenial HWE) vulnerabilities2018-04-05
Ubuntu
Linux kernel vulnerabilities2018-04-04
Ubuntu
Linux kernel (Raspberry Pi 2) vulnerabilities2018-04-04

💬Community

2
Bugzilla
CVE-2017-0861 kernel: Use-after-free in snd_pcm_info function in ALSA subsystem potentially leads to privilege escalation2018-04-05
Bugzilla
CVE-2017-0861 kernel: Use-after-free in snd_pcm_info function in ALSA subsystem potentially leads to privilege escalation [fedora-all]2018-04-05
CVE-2017-0861 — Use After Free in Google INC Android | cvebase