An integer overflow was found in snd_compr_allocate_buffer(), that could result into allocating smaller buffer than expected. Upstream patch: https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=b35cc8225845112a616e3a2266d2fde5ab13d3ab The patch was incomplete and introduced another issues known as CVE-2014-9904. CVE assignment: http://seclists.org/oss-sec/2016/q2/616