Bug 2129859 (CVE-2022-3303) - CVE-2022-3303 kernel: race condition in snd_pcm_oss_sync leads to NULL pointer dereference
Summary: CVE-2022-3303 kernel: race condition in snd_pcm_oss_sync leads to NULL pointe...
Keywords:
Status: NEW
Alias: CVE-2022-3303
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
low
low
Target Milestone: ---
Assignee: Nobody
QA Contact:
URL:
Whiteboard:
Depends On: 2129874 2129878 2129879 2129880 2129881
Blocks: 2126492
TreeView+ depends on / blocked
 
Reported: 2022-09-26 13:12 UTC by Mauro Matteo Cascella
Modified: 2023-09-19 14:13 UTC (History)
49 users (show)

Fixed In Version: kernel 6.0-rc5
Doc Type: If docs needed, set a value
Doc Text:
A race condition flaw was found in the Linux kernel sound subsystem due to improper locking. It could lead to a NULL pointer dereference while handling the SNDCTL_DSP_SYNC ioctl. A privileged local user (root or member of the audio group) could use this flaw to crash the system, resulting in a denial of service condition.
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description Mauro Matteo Cascella 2022-09-26 13:12:27 UTC
A race condition issue leading to NULL pointer dereference was found in the Linux kernel sound subsystem. A privileged local user (root or member of the audio group) could use this flaw to crash the system, resulting in a denial of service condition.

Reference and upstream patch:
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=8423f0b6d513b259fdab9c9bf4aaa6188d054c2d
https://lore.kernel.org/all/CAFcO6XN7JDM4xSXGhtusQfS2mSBcx50VJKwQpCq=WeLt57aaZA@mail.gmail.com/

Comment 1 Mauro Matteo Cascella 2022-09-26 14:06:40 UTC
Created kernel tracking bugs for this issue:

Affects: fedora-all [bug 2129874]

Comment 3 Justin M. Forbes 2022-09-28 15:57:32 UTC
This was fixed for Fedora with the 5.19.9 stable kernel updates.


Note You need to log in before you can comment on or make changes to this bug.