CVE-2016-9794 PUBLISHED

Race condition in the snd_pcm_period_elapsed function in sound/core/pcm_lib.c in the ALSA subsystem in the Linux kernel before 4.7 allows local users to cause a denial of service (use-after-free) or possibly have unspecified other impact via a crafted SNDRV_PCM_TRIGGER_START command.

EPSS 0.05% · 17.0th percentile

Risk Scores

EPSS Score
0.05%
17.0th percentile

Affected Products

VendorProductVersions
Ubuntu:24.04:LTSlinux-gcp-6.116.11.0-1011.11~24.04.1, 6.11.0-1006.6~24.04.2, 0
Ubuntu:20.04:LTSlinux-riscv5.4.0-33.37, 5.4.0-31.35, 5.4.0-30.34
Ubuntu:20.04:LTSlinux-gkeop5.4.0-1081.85, 5.4.0-1080.84, 5.4.0-1079.83
Ubuntu:24.04:LTSlinux-riscv6.8.0-56.58.1, 6.8.0-53.55.1, 6.8.0-52.53.1
Ubuntu:16.04:LTSlinux-aws4.4.0-1001.10, 0
Ubuntu:Pro:20.04:LTSlinux-azure-fde-5.155.15.0-1060.69~20.04.1.1, 5.15.0-1059.67~20.04.1.1, 5.15.0-1058.66~20.04.2.1
Ubuntu:16.04:LTSlinux-snapdragon4.4.0-1042.46, 4.4.0-1039.43, 4.4.0-1035.39
Ubuntu:18.04:LTSlinux-hwe5.3.0-53.47~18.04.1, 0, 4.18.0-13.14~18.04.1
Ubuntu:18.04:LTSlinux-azure5.0.0-1035.37, 4.15.0-1009.9, 4.15.0-1012.12
Ubuntu:20.04:LTSlinux-raspi25.3.0-1015.17, 5.3.0-1017.19, 5.4.0-1004.4
Ubuntu:20.04:LTSlinux-gke0, 5.4.0-1091.98, 5.4.0-1090.97
Ubuntu:18.04:LTSlinux-gcp4.15.0-1019.20, 4.15.0-1021.22, 4.15.0-1023.24
Ubuntu:16.04:LTSlinux4.3.0-7.18, 4.4.0-14.30, 4.4.0-13.29
Ubuntu:22.04:LTSlinux-intel-iot-realtime0, 5.15.0-1073.75
Ubuntu:24.04:LTSlinux-lowlatency-hwe-6.116.11.0-1016.17~24.04.1, 6.11.0-1014.15~24.04.1, 6.11.0-1015.16~24.04.2
Ubuntu:24.04:LTSlinux-azure-6.116.11.0-1008.8~24.04.1, 6.11.0-1012.12~24.04.1, 6.11.0-1013.13~24.04.1
Ubuntu:14.04:LTSlinux-lts-vivid3.19.0-66.74~14.04.1, 3.19.0-65.73~14.04.1, 3.19.0-61.69~14.04.1
Ubuntu:16.04:LTSlinux-raspi24.4.0-1016.22, 4.4.0-1017.23, 4.4.0-1019.25
Ubuntu:14.04:LTSlinux3.13.0-40.69, 0, 3.11.0-12.19
Ubuntu:24.04:LTSlinux-realtime0, 6.8.1-1015.16

…and 7 more

Timeline

References

Open in Interactive Console →