sound/core/timer.c in the Linux kernel before 4.11.5 is vulnerable to a data race in the ALSA /dev/snd/timer driver resulting in local users being able to read information belonging to other users, i.e., uninitialized memory contents may be disclosed when a read and an ioctl happen at the same time.
References
Configurations
Information
Published : 2017-06-17 11:29
Updated : 2017-12-05 18:29
NVD link : CVE-2017-1000380
Mitre link : CVE-2017-1000380
JSON object : View
CWE
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor
Products Affected
linux
- linux_kernel