peter bassill · operator
$ cve CVE-2016-4578 JSON

CVE-2016-4578 EXPLOIT

5.5
MEDIUM · CVSS 3.0 · EPSS 1.2% (pctl 67)

Patch early

A public exploit exists.

Description

sound/core/timer.c in the Linux kernel through 4.6 does not initialize certain r1 data structures, which allows local users to obtain sensitive information from kernel stack memory via crafted use of the ALSA timer interface, related to the (1) snd_timer_user_ccallback and (2) snd_timer_user_tinterrupt functions.

Scoring

CVSS5.5 (MEDIUM, v3.0)
VectorCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
EPSS1.2% — more likely to be exploited than 67% of all CVEs
WeaknessCWE-200
On CISA KEVno
Public exploityes
Published2016-05-23
Last modified2026-06-17

Affected (11)

VendorProduct
canonicalubuntu linux
debiandebian linux
linuxlinux kernel
opensuseleap
opensuseopensuse
redhatenterprise linux desktop
redhatenterprise linux server
redhatenterprise linux server aus
redhatenterprise linux server eus
redhatenterprise linux server tus
redhatenterprise linux workstation

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD