CVE-2014-4652

low
New! CVE Severity Now Using CVSS v3

The calculated severity for CVEs has been updated to use CVSS v3 by default. CVEs that do not have a CVSS v3 score will fall back CVSS v2 for calculating severity. Severity display preferences can be toggled in the settings dropdown.

Description

Race condition in the tlv handler functionality in the snd_ctl_elem_user_tlv function in sound/core/control.c in the ALSA control implementation in the Linux kernel before 3.15.2 allows local users to obtain sensitive information from kernel memory by leveraging /dev/snd/controlCX access.

References

http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=07f4d9d74a04aa7c72c5dae0ef97565f28f17b92

http://lists.opensuse.org/opensuse-security-announce/2015-04/msg00020.html

http://rhn.redhat.com/errata/RHSA-2014-1083.html

http://rhn.redhat.com/errata/RHSA-2015-1272.html

http://secunia.com/advisories/59434

http://secunia.com/advisories/59777

http://secunia.com/advisories/60545

http://secunia.com/advisories/60564

http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.15.2

http://www.openwall.com/lists/oss-security/2014/06/26/6

http://www.ubuntu.com/usn/USN-2334-1

http://www.ubuntu.com/usn/USN-2335-1

https://bugzilla.redhat.com/show_bug.cgi?id=1113406

https://exchange.xforce.ibmcloud.com/vulnerabilities/94412

https://github.com/torvalds/linux/commit/07f4d9d74a04aa7c72c5dae0ef97565f28f17b92

Details

Source: MITRE

Published: 2014-07-03

Updated: 2020-08-14

Type: CWE-362

Risk Information

CVSS v2

Base Score: 1.9

Vector: AV:L/AC:M/Au:N/C:P/I:N/A:N

Impact Score: 2.9

Exploitability Score: 3.4

Severity: LOW

Tenable Plugins

View all (30 total)

IDNameProductFamilySeverity
124985EulerOS Virtualization for ARM 64 3.0.1.0 : kernel (EulerOS-SA-2019-1532)NessusHuawei Local Security Checks
high
124805EulerOS Virtualization 3.0.1.0 : kernel (EulerOS-SA-2019-1481)NessusHuawei Local Security Checks
high
99163OracleVM 3.3 : Unbreakable / etc (OVMSA-2017-0057) (Dirty COW)NessusOracleVM Local Security Checks
critical
85198Scientific Linux Security Update : kernel on SL6.x i386/x86_64 (20150722)NessusScientific Linux Local Security Checks
medium
85097Oracle Linux 6 : kernel (ELSA-2015-1272)NessusOracle Linux Local Security Checks
high
85010CentOS 6 : kernel (CESA-2015:1272)NessusCentOS Local Security Checks
medium
84936RHEL 6 : kernel (RHSA-2015:1272)NessusRed Hat Local Security Checks
medium
83723SUSE SLES10 Security Update : kernel (SUSE-SU-2015:0812-1)NessusSuSE Local Security Checks
high
83640SUSE SLES11 Security Update : kernel (SUSE-SU-2014:1138-1)NessusSuSE Local Security Checks
medium
83633SUSE SLES11 Security Update : kernel (SUSE-SU-2014:1105-1)NessusSuSE Local Security Checks
high
82691OracleVM 3.3 : kernel-uek (OVMSA-2015-0040)NessusOracleVM Local Security Checks
high
81966Oracle Linux 6 / 7 : Unbreakable Enterprise kernel (ELSA-2015-3012)NessusOracle Linux Local Security Checks
high
81800Oracle Linux 7 : kernel (ELSA-2015-0290)NessusOracle Linux Local Security Checks
high
80014Scientific Linux Security Update : kernel on SL7.x x86_64 (20141209)NessusScientific Linux Local Security Checks
high
80006Oracle Linux 5 / 6 : Unbreakable Enterprise kernel (ELSA-2014-3105)NessusOracle Linux Local Security Checks
medium
80005Oracle Linux 5 / 6 : Unbreakable Enterprise kernel (ELSA-2014-3104)NessusOracle Linux Local Security Checks
medium
80004Oracle Linux 6 / 7 : Unbreakable Enterprise kernel (ELSA-2014-3103)NessusOracle Linux Local Security Checks
medium
79876CentOS 7 : kernel (CESA-2014:1971)NessusCentOS Local Security Checks
high
79848RHEL 7 : kernel (RHSA-2014:1971)NessusRed Hat Local Security Checks
high
79845Oracle Linux 7 : kernel (ELSA-2014-1971)NessusOracle Linux Local Security Checks
high
77492Ubuntu 14.04 LTS : linux vulnerabilities (USN-2337-1)NessusUbuntu Local Security Checks
medium
77491Ubuntu 12.04 LTS : linux-lts-trusty vulnerabilities (USN-2336-1)NessusUbuntu Local Security Checks
medium
77490Ubuntu 12.04 LTS : linux vulnerabilities (USN-2334-1)NessusUbuntu Local Security Checks
high
77489Ubuntu 10.04 LTS : linux-ec2 vulnerabilities (USN-2333-1)NessusUbuntu Local Security Checks
medium
77488Ubuntu 10.04 LTS : linux vulnerabilities (USN-2332-1)NessusUbuntu Local Security Checks
medium
77298RHEL 6 : MRG (RHSA-2014:1083)NessusRed Hat Local Security Checks
high
77177openSUSE Security Update : kernel (openSUSE-SU-2014:0985-1)NessusSuSE Local Security Checks
high
77074Mandriva Linux Security Advisory : kernel (MDVSA-2014:155)NessusMandriva Local Security Checks
medium
76988openSUSE Security Update : kernel (openSUSE-SU-2014:0957-1)NessusSuSE Local Security Checks
medium
76557SuSE 11.3 Security Update : Linux kernel (SAT Patch Numbers 9488 / 9491 / 9493)NessusSuSE Local Security Checks
critical