CVE Database
/

CVE-2014-4652

Back to search

CVE-2014-4652

Published: Jul 3, 2014

Modified: Aug 6, 2024

PUBLISHED

Description

Race condition in the tlv handler functionality in the snd_ctl_elem_user_tlv function in sound/core/control.c in the ALSA control implementation in the Linux kernel before 3.15.2 allows local users to obtain sensitive information from kernel memory by leveraging /dev/snd/controlCX access.

VendorProductVersions

n/a

n/a

affected
n/a

References

60545
third-party-advisory
x_refsource_SECUNIA
USN-2335-1
vendor-advisory
x_refsource_UBUNTU
USN-2334-1
vendor-advisory
x_refsource_UBUNTU
60564
third-party-advisory
x_refsource_SECUNIA
RHSA-2014:1083
vendor-advisory
x_refsource_REDHAT
59777
third-party-advisory
x_refsource_SECUNIA
59434
third-party-advisory
x_refsource_SECUNIA
RHSA-2015:1272
vendor-advisory
x_refsource_REDHAT
SUSE-SU-2015:0812
vendor-advisory
x_refsource_SUSE

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now