CVE-2017-13167Race Condition in INC Android

CWE-362Race Condition7 documents7 sources
Severity
7.8HIGHNVD
EPSS
0.1%
top 75.51%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 6
Latest updateMay 13

Description

An elevation of privilege vulnerability in the kernel sound timer. Product: Android. Versions: Android kernel. Android ID A-37240993.

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages2 packages

CVEListV5google_inc/androidAndroid kernel
Debianlinux/linux_kernel< 4.4.2-1+3

🔴Vulnerability Details

3
GHSA
GHSA-pg9w-32jf-9x5r: An elevation of privilege vulnerability in the kernel sound timer2022-05-13
OSV
CVE-2017-13167: An elevation of privilege vulnerability in the kernel sound timer2017-12-06
CVEList
CVE-2017-13167: An elevation of privilege vulnerability in the kernel sound timer2017-12-06

📋Vendor Advisories

2
Debian
CVE-2017-13167: linux - An elevation of privilege vulnerability in the kernel sound timer. Product: Andr...2017
Red Hat
kernel: sound: a race condition in the kernel sound timer in snd_timer_user_read()2016-02-09

💬Community

1
Bugzilla
CVE-2017-13167 kernel: sound: a race condition in the kernel sound timer in snd_timer_user_read()2018-04-18
CVE-2017-13167 — Race Condition in Google INC Android | cvebase