7.8
CVSSv3

CVE-2014-9904

Published: 27/06/2016 Updated: 17/01/2023
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 641
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

The snd_compress_check_input function in sound/core/compress_offload.c in the ALSA subsystem in the Linux kernel prior to 3.17 does not properly check for an integer overflow, which allows local users to cause a denial of service (insufficient memory allocation) or possibly have unspecified other impact via a crafted SNDRV_COMPRESS_SET_PARAMS ioctl call.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

linux linux kernel

debian debian linux 8.0

novell suse linux enterprise real time extension 12

Vendor Advisories

Several security issues were fixed in the kernel ...
Several security issues were fixed in the kernel ...
The snd_compress_check_input function in sound/core/compress_offloadc in the ALSA subsystem in the Linux kernel before 317 does not properly check for an integer overflow, which allows local users to cause a denial of service (insufficient memory allocation) or possibly have unspecified other impact via a crafted SNDRV_COMPRESS_SET_PARAMS ioctl c ...