Buffer overflow in Linux kernel - CVE-2019-15117
Published: September 6, 2019
Linux kernel
Detailed vulnerability description
The vulnerability allows a local user to execute arbitrary code on the target system.
The vulnerability exists due to the "parse_audio_mixer_unit" in "sound/usb/mixer.c" mishandles a short descriptor. A local authenticated user can trigger memory corruption and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.