We found results for “”
CVE-2016-2547
Good to know:
Date: April 27, 2016
sound/core/timer.c in the Linux kernel before 4.4.1 employs a locking approach that does not consider slave timer instances, which allows local users to cause a denial of service (race condition, use-after-free, and system crash) via a crafted ioctl call.
Language: C
Severity Score
Related Resources (25)
Severity Score
Weakness Type (CWE)
Race Conditions
CWE-362Top Fix
Upgrade Version
Upgrade to version v4.5-rc1,v3.12.54,v3.14.60,v3.16.35,v3.18.27,v3.2.77,v4.1.17,v4.3.5,v4.4.1
CVSS v3.1
Base Score: |
|
---|---|
Attack Vector (AV): | LOCAL |
Attack Complexity (AC): | HIGH |
Privileges Required (PR): | NONE |
User Interaction (UI): | NONE |
Scope (S): | UNCHANGED |
Confidentiality (C): | NONE |
Integrity (I): | NONE |
Availability (A): | HIGH |
CVSS v2
Base Score: |
|
---|---|
Access Vector (AV): | LOCAL |
Access Complexity (AC): | MEDIUM |
Authentication (AU): | NONE |
Confidentiality (C): | NONE |
Integrity (I): | NONE |
Availability (A): | COMPLETE |
Additional information: |