7.2
CVE-2011-1169
- EPSS 0.44%
- Veröffentlicht 03.05.2011 19:55:07
- Zuletzt bearbeitet 16.06.2026 23:28:51
- CVE-Watchlists
- Unerledigt
Array index error in the asihpi_hpi_ioctl function in sound/pci/asihpi/hpioctl.c in the AudioScience HPI driver in the Linux kernel before 2.6.38.1 might allow local users to cause a denial of service (memory corruption) or possibly gain privileges via a crafted adapter index value that triggers access to an invalid kernel pointer.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Linux ≫ Linux Kernel Version < 2.6.38.1
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.44% | 0.35 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 7.2 | 3.9 | 10 |
AV:L/AC:L/Au:N/C:C/I:C/A:C
|
CWE-129 Improper Validation of Array Index
The product uses untrusted input when calculating or using an array index, but the product does not validate or incorrectly validates the index to ensure the index references a valid position within the array.
http://git.kernel.org/?p=linux/kernel/git/tiwai/sound-2.6.git%3Ba=commit%3Bh=4a122c10fbfe9020df469f0f669da129c5757671
http://openwall.com/lists/oss-security/2011/03/18/1
http://openwall.com/lists/oss-security/2011/03/18/2
http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.38.1
https://bugzilla.redhat.com/show_bug.cgi?id=688898