CVE Vulnerabilities

CVE-2007-4571

Published: Sep 26, 2007 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
2.1 LOW
AV:L/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
LOW
root.io logo minimus.io logo echo.ai logo

The snd_mem_proc_read function in sound/core/memalloc.c in the Advanced Linux Sound Architecture (ALSA) in the Linux kernel before 2.6.22.8 does not return the correct write size, which allows local users to obtain sensitive information (kernel memory contents) via a small count argument, as demonstrated by multiple reads of /proc/driver/snd-page-alloc.

Affected Software

NameVendorStart VersionEnd Version
Linux_kernelLinux*2.6.22.7 (including)
Red Hat Enterprise Linux 4RedHatkernel-0:2.6.9-55.0.12.EL*
Red Hat Enterprise Linux 5RedHatkernel-0:2.6.18-53.1.4.el5*
LinuxUbuntuupstream*
Linux-source-2.6.15Ubuntudapper*
Linux-source-2.6.17Ubuntuedgy*
Linux-source-2.6.20Ubuntufeisty*
Linux-source-2.6.22Ubuntugutsy*

References