First published: Thu Jun 21 2012(Updated: )
Integer underflow in the Open Sound System (OSS) subsystem in the Linux kernel before 2.6.39 on unspecified non-x86 platforms allows local users to cause a denial of service (memory corruption) by leveraging write access to /dev/sequencer.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
debian/linux-2.6 | ||
Linux kernel | =2.6.38-rc7 | |
Linux kernel | =2.6.38-rc6 | |
Linux kernel | =2.6.38-rc4 | |
Linux kernel | =2.6.38.3 | |
Linux kernel | <=2.6.38.8 | |
Linux kernel | =2.6.38-rc3 | |
Linux kernel | =2.6.38-rc5 | |
Linux kernel | =2.6.38-rc2 | |
Linux kernel | =2.6.38.6 | |
Linux kernel | =2.6.38.1 | |
Linux kernel | =2.6.38-rc1 | |
Linux kernel | =2.6.38.5 | |
Linux kernel | =2.6.38.2 | |
Linux kernel | =2.6.38 | |
Linux kernel | =2.6.38-rc8 | |
Linux kernel | =2.6.38.4 | |
Linux kernel | =2.6.38.7 | |
Linux Kernel | <=2.6.38.8 | |
Linux Kernel | =2.6.38 | |
Linux Kernel | =2.6.38-rc1 | |
Linux Kernel | =2.6.38-rc2 | |
Linux Kernel | =2.6.38-rc3 | |
Linux Kernel | =2.6.38-rc4 | |
Linux Kernel | =2.6.38-rc5 | |
Linux Kernel | =2.6.38-rc6 | |
Linux Kernel | =2.6.38-rc7 | |
Linux Kernel | =2.6.38-rc8 | |
Linux Kernel | =2.6.38.1 | |
Linux Kernel | =2.6.38.2 | |
Linux Kernel | =2.6.38.3 | |
Linux Kernel | =2.6.38.4 | |
Linux Kernel | =2.6.38.5 | |
Linux Kernel | =2.6.38.6 | |
Linux Kernel | =2.6.38.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-1476 is classified as a medium severity vulnerability due to its potential to cause a denial of service through memory corruption.
To fix CVE-2011-1476, upgrade to the Linux kernel version 2.6.39 or later, which addresses this integer underflow issue.
CVE-2011-1476 affects users with unspecified non-x86 platforms running Linux kernel versions prior to 2.6.39.
The impact of CVE-2011-1476 includes potential denial of service conditions resulting from memory corruption when a local user interacts with /dev/sequencer.
CVE-2011-1476 is less relevant for current Linux systems, as supported versions have long since implemented fixes for this vulnerability.