Lucene search

K
ubuntucveUbuntu.comUB:CVE-2014-4654
HistoryJul 03, 2014 - 12:00 a.m.

CVE-2014-4654

2014-07-0300:00:00
ubuntu.com
ubuntu.com
23

4.6 Medium

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:L/Au:N/C:P/I:P/A:P

0.0004 Low

EPSS

Percentile

10.1%

The snd_ctl_elem_add function in sound/core/control.c in the ALSA control
implementation in the Linux kernel before 3.15.2 does not check
authorization for SNDRV_CTL_IOCTL_ELEM_REPLACE commands, which allows local
users to remove kernel controls and cause a denial of service
(use-after-free and system crash) by leveraging /dev/snd/controlCX access
for an ioctl call.

Bugs

Notes

Author Note
jdstrand android kernels (goldfish, grouper, maguro, mako and manta) are not supported on the Ubuntu Touch 13.10 preview kernels android kernels (flo, goldfish, grouper, maguro, mako and manta) are not supported on the Ubuntu Touch 14.04 preview kernels linux-lts-saucy no longer receives official support linux-lts-quantal no longer receives official support
OSVersionArchitecturePackageVersionFilename
ubuntu10.04noarchlinux< 2.6.32-65.131UNKNOWN
ubuntu12.04noarchlinux< 3.2.0-68.102UNKNOWN
ubuntu14.04noarchlinux< 3.13.0-35.62UNKNOWN
ubuntu12.04noarchlinux-armadaxp< 3.2.0-1637.54UNKNOWN
ubuntu10.04noarchlinux-ec2< 2.6.32-369.85UNKNOWN
ubuntu12.04noarchlinux-lts-trusty< 3.13.0-35.62~precise1UNKNOWN
ubuntu12.04noarchlinux-ti-omap4< 3.2.0-1452.72UNKNOWN

4.6 Medium

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:L/Au:N/C:P/I:P/A:P

0.0004 Low

EPSS

Percentile

10.1%