Tracker / CVE-2014-9904
CVE-2014-9904
High 7.8
The snd_compress_check_input function in sound/core/compress_offload.c in the ALSA subsystem in the Linux kernel before 3.17 does not properly check for an integer overflow, which allows local users to cause a denial of service (insufficient memory allocation) or possibly have unspecified other impact via a crafted SNDRV_COMPRESS_SET_PARAMS ioctl call.
Affected products and versions
| debian | debian_linux |
|---|---|
| linux | linux_kernel · 3.13 → 3.16.37 |
| linux | linux_kernel · 3.7 → 3.12.62 |
| novell | suse_linux_enterprise_real_time_extension |
Analysis
This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.