Race condition in the sndpcmperiodelapsed function in sound/core/pcmlib.c in the ALSA subsystem in the Linux kernel before 4.7 allows local users to cause a denial of service (use-after-free) or possibly have unspecified other impact via a crafted SNDRVPCMTRIGGER_START command.
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2016-9794.json"
[
{
"signature_type": "Line",
"deprecated": false,
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git@3aa02cb664c5fb1042958c8d1aa8c35055a2ebc4",
"id": "CVE-2016-9794-183122ee",
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"45240515257066432476650329599380269889",
"210157992404258032174687633529991664151",
"83640800547620040778080427991973203069",
"4570771304419075773429903052296999553",
"75038398212307388993246207579675057736"
]
},
"target": {
"file": "sound/core/pcm_lib.c"
}
},
{
"signature_type": "Function",
"deprecated": false,
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git@3aa02cb664c5fb1042958c8d1aa8c35055a2ebc4",
"id": "CVE-2016-9794-4cc09b2b",
"signature_version": "v1",
"digest": {
"length": 408.0,
"function_hash": "30520346123408933525110712100607230091"
},
"target": {
"file": "sound/core/pcm_lib.c",
"function": "snd_pcm_period_elapsed"
}
}
]
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2016-9794.json"
[
{
"signature_type": "Line",
"deprecated": false,
"source": "https://github.com/torvalds/linux/commit/3aa02cb664c5fb1042958c8d1aa8c35055a2ebc4",
"id": "CVE-2016-9794-84eafb7f",
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"45240515257066432476650329599380269889",
"210157992404258032174687633529991664151",
"83640800547620040778080427991973203069",
"4570771304419075773429903052296999553",
"75038398212307388993246207579675057736"
]
},
"target": {
"file": "sound/core/pcm_lib.c"
}
},
{
"signature_type": "Function",
"deprecated": false,
"source": "https://github.com/torvalds/linux/commit/3aa02cb664c5fb1042958c8d1aa8c35055a2ebc4",
"id": "CVE-2016-9794-d399a937",
"signature_version": "v1",
"digest": {
"length": 408.0,
"function_hash": "30520346123408933525110712100607230091"
},
"target": {
"file": "sound/core/pcm_lib.c",
"function": "snd_pcm_period_elapsed"
}
}
]