CVE-2007-4571
Last modified
CVE-2007-4571 is a vulnerability of currently unknown severity. The snd_mem_proc_read function in sound/core/memalloc.c in the Advanced Linux Sound Architecture (ALSA) in the Linux kernel before 2.6.22.8 does not return the correct write size, which allows local users to obtain sensitive information (kernel memory contents) via a small count argument, as demonstrated by multiple reads of /proc/driver/snd-page-alloc.. EPSS estimates a 0.76% chance of exploitation in the next 30 days.
Description
The snd_mem_proc_read function in sound/core/memalloc.c in the Advanced Linux Sound Architecture (ALSA) in the Linux kernel before 2.6.22.8 does not return the correct write size, which allows local users to obtain sensitive information (kernel memory contents) via a small count argument, as demonstrated by multiple reads of /proc/driver/snd-page-alloc.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux Kernel | <= 2.6.22.7 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2007-4571?
How severe is CVE-2007-4571?
How do I fix CVE-2007-4571?
Are you affected by CVE-2007-4571?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
