A use after free vulnerability exists in the ALSA PCM package in the Linux Kernel. SNDRV_CTL_IOCTL_ELEM_{READ|WRITE}32 is missing locks that can be used in a use-after-free that can result in a priviledge escalation to gain ring0 access from the system user. We recommend upgrading past commit 56b88b50565cd8b946a2d00b0c83927b7ebb055e
| Software | From | Fixed in |
|---|---|---|
| linux / linux_kernel | 4.15 | 4.19.270 |
| linux / linux_kernel | 4.20 | 5.4.229 |
| linux / linux_kernel | 5.5 | 5.10.163 |
| linux / linux_kernel | 5.16 | 6.1.6 |
| linux / linux_kernel | 5.11 | 5.15.88 |
| linux / linux_kernel | 4.14 | 4.14.303 |
| debian / debian_linux | 10.0 | 10.0.x |