[USN-3169-4] Linux kernel (Qualcomm Snapdragon) vulnerabilities

Severity Low
Affected Packages 1
CVEs 2

Several security issues were fixed in the kernel.

Baozeng Ding discovered a race condition that could lead to a use-after-
free in the Advanced Linux Sound Architecture (ALSA) subsystem of the Linux
kernel. A local attacker could use this to cause a denial of service
(system crash). (CVE-2016-9794)

Andrey Konovalov discovered that signed integer overflows existed in the
setsockopt() system call when handling the SO_SNDBUFFORCE and
SO_RCVBUFFORCE options. A local attacker with the CAP_NET_ADMIN capability
could use this to cause a denial of service (system crash or memory
corruption). (CVE-2016-9793)

Package Affected Version
pkg:deb/ubuntu/linux-image-4.4.0-1044-snapdragon?distro=xenial < 4.4.0-1044.48
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:deb/ubuntu/linux-image-4.4.0-1044-snapdragon?distro=xenial ubuntu linux-image-4.4.0-1044-snapdragon < 4.4.0-1044.48 xenial
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...