CVE-2010-4527 PUBLISHED CVSS 6.900000095367432 MEDIUM

The load_mixer_volumes function in sound/oss/soundcard.c in the OSS sound subsystem in the Linux kernel before 2.6.37 incorrectly expects that a certain name field ends with a '\0' character, which allows local users to conduct buffer overflow attacks and gain privileges, or possibly obtain sensitive information from kernel memory, via a SOUND_MIXER_SETLEVELS ioctl call.

EPSS 0.05% · 15.4th percentile

Risk Scores

CVSS v2.0
6.900000095367432
EPSS Score
0.05%
15.4th percentile

Affected Products

VendorProductVersions
n/an/an/a
linuxlinux_kernel0

Timeline

References

Open in Interactive Console →