Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The load_mixer_volumes function in sound/oss/soundcard.c in the OSS sound subsystem in the Linux kernel before 2.6.37 incorrectly expects that a certain name field ends with a '\0' character, which allows local users to conduct buffer overflow attacks and gain privileges, or possibly obtain sensitive information from kernel memory, via a SOUND_MIXER_SETLEVELS ioctl call.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Linux kernel OSS声音子系统load_mixer_volumes函数缓冲区错误漏洞
Vulnerability Description
Linux kernel是美国Linux基金会发布的开源操作系统Linux所使用的内核。NFSv4 implementation是其中的一个分布式文件系统协议。 Linux kernel 2.6.37之前版本中的OSS声音子系统中的sound/oss/soundcard.c文件中的load_mixer_volumes函数错误的认为某个名称字段以''字符结尾。本地用户可以借助SOUND_MIXER_SETLEVELS输入输出控制调用进行缓冲区溢出攻击并获得权限,或者可能从内核栈内存中获取敏感信息。
CVSS Information
N/A
Vulnerability Type
N/A