PT-2016-4997 · Linux+1 · Linux Kernel+1
Published
2015-06-03
·
Updated
2020-07-31
·
CVE-2016-2068
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel versions 3.x
Description
The issue allows attackers to gain privileges or cause a denial of service via a crafted application. This can be achieved by performing either an AUDIO EFFECTS WRITE or AUDIO EFFECTS READ operation. The exploitation is possible due to integer overflow and buffer overflow or buffer over-read in the MSM QDSP6 audio driver.
Recommendations
For Linux kernel version 3.x, consider restricting access to the AUDIO EFFECTS WRITE and AUDIO EFFECTS READ operations until a patch is available. As a temporary workaround, disabling the vulnerable MSM QDSP6 audio driver may help minimize the risk of exploitation.
Fix
DoS
Integer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Linux Kernel