SB2017062839 - Out-of-bounds read in Linux kernel
Published: June 28, 2017
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Out-of-bounds read (CVE-ID: CVE-2017-9986)
The vulnerability allows a local user to execute arbitrary code.
The intr function in sound/oss/msnd_pinnacle.c in the Linux kernel through 4.11.7 allows local users to cause a denial of service (over-boundary access) or possibly have unspecified other impact by changing the value of a message queue head pointer between 2 kernel reads of that value, aka a 'double fetch' vulnerability.
Remediation
Install update from vendor's website.