UBUNTU-CVE-2017-15265
Dashboard / Vulnerabilities / UBUNTU-CVE-2017-15265
UBUNTU-CVE-2017-15265
Summary:
Details: Race condition in the ALSA subsystem in the Linux kernel before 4.13.8 allows local users to cause a denial of service (use-after-free) or possibly have unspecified other impact via crafted /dev/snd/seq ioctl calls, related to sound/core/seq/seq_clientmgr.c and sound/core/seq/seq_ports.c.
References: https://ubuntu.com/security/CVE-2017-15265, https://bugzilla.suse.com/show_bug.cgi?id=1062520, http://mailman.alsa-project.org/pipermail/alsa-devel/2017-October/126292.html, https://ubuntu.com/security/notices/USN-3485-1, https://ubuntu.com/security/notices/USN-3485-2, https://ubuntu.com/security/notices/USN-3487-1, https://ubuntu.com/security/notices/USN-3485-3, https://ubuntu.com/security/notices/USN-3698-1, https://ubuntu.com/security/notices/USN-3698-2, https://www.cve.org/CVERecord?id=CVE-2017-15265
Affected packages
Package
Name: linux
Purl: pkg:deb/ubuntu/linux?arch=source&distro=trusty
Affected ranges
Type: ECOSYSTEM
Events:
