CVE-2022-3170
Summary
| CVE | CVE-2022-3170 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-09-13 16:15:00 UTC |
| Updated | 2022-12-08 22:06:00 UTC |
| Description | An out-of-bounds access issue was found in the Linux kernel sound subsystem. It could occur when the 'id->name' provided by the user did not end with '\0'. A privileged local user could pass a specially crafted name through ioctl() interface and crash the system or potentially escalate their privileges on the system. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| ALSA: control: Re-order bounds checking in get_ctl_id_hash() · torvalds/linux@5934d9a · GitHub |
MISC |
github.com |
|
| ALSA: control: Fix an out-of-bounds bug in get_ctl_id_hash() · torvalds/linux@6ab55ec · GitHub |
MISC |
github.com |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 903910 Common Base Linux Mariner (CBL-Mariner) Security Update for kernel (10948)
- 903942 Common Base Linux Mariner (CBL-Mariner) Security Update for kernel (10924)
- 904107 Common Base Linux Mariner (CBL-Mariner) Security Update for kernel (10948-1)
- 904246 Common Base Linux Mariner (CBL-Mariner) Security Update for kernel (10924-1)
- 905752 Common Base Linux Mariner (CBL-Mariner) Security Update for kernel (10948-2)
- 906433 Common Base Linux Mariner (CBL-Mariner) Security Update for kernel (10924-2)