CVE-2016-9794: Use After Free
A use-after-free vulnerability was found in ALSA pcm layer, which allows local users to cause a denial of service, memory corruption or possibly other unspecified impact. Due to the nature of the flaw, privilege escalation cannot be fully ruled out, although we believe it is unlikely.
References:
https://patchwork.kernel.org/patch/8752621/
Upstream patch:
https://github.com/torvalds/linux/commit/3aa02cb664c5fb1042958c8d1aa8c35055a2ebc4
CVE-ID request+assign:
http://seclists.org/oss-sec/2016/q4/575
Other sources
Race condition in the sndpcmperiodelapsed function in sound/core/pcmlib.c in the ALSA subsystem in the Linux kernel before 4.7 allows local users to cause a denial of service (use-after-free) or possibly have unspecified other impact via a crafted SNDRVPCMTRIGGERSTART command.
— MITRE
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2016-9794?
CVE-2016-9794 is considered a high severity vulnerability due to potential for denial of service and memory corruption.
How do I fix CVE-2016-9794?
To fix CVE-2016-9794, update your Linux kernel to a version higher than 4.7 or install the recommended Debian packages.
Which systems are affected by CVE-2016-9794?
CVE-2016-9794 affects multiple versions of the Linux kernel and Android systems prior to updates that address the vulnerability.
What are the potential impacts of CVE-2016-9794?
The potential impacts of CVE-2016-9794 include denial of service, memory corruption, and possibly privilege escalation.
Can CVE-2016-9794 affect my Android device?
Yes, CVE-2016-9794 can affect Android devices running vulnerable versions of the operating system.