PublicDateAtUSN: 2011-05-03 Candidate: CVE-2011-1169 PublicDate: 2011-05-03 19:55:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1169 http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.38.1 https://ubuntu.com/security/notices/USN-1160-1 https://ubuntu.com/security/notices/USN-1167-1 https://ubuntu.com/security/notices/USN-1187-1 https://ubuntu.com/security/notices/USN-1202-1 Description: Array index error in the asihpi_hpi_ioctl function in sound/pci/asihpi/hpioctl.c in the AudioScience HPI driver in the Linux kernel before 2.6.38.1 might allow local users to cause a denial of service (memory corruption) or possibly gain privileges via a crafted adapter index value that triggers access to an invalid kernel pointer. Ubuntu-Description: Dan Rosenberg discovered that some ALSA drivers did not correctly check the adapter index during ioctl calls. If this driver was loaded, a local attacker could make a specially crafted ioctl call to gain root privileges. Notes: Bugs: https://bugzilla.redhat.com/show_bug.cgi?id=688898 Priority: medium Discovered-by: Dan Rosenberg Assigned-to: CVSS: Patches_linux-source-2.6.15: upstream_linux-source-2.6.15: released (2.6.39~rc1) dapper_linux-source-2.6.15: ignored (reached end-of-life) hardy_linux-source-2.6.15: DNE lucid_linux-source-2.6.15: DNE maverick_linux-source-2.6.15: DNE natty_linux-source-2.6.15: DNE devel_linux-source-2.6.15: DNE Patches_linux: upstream: http://git.kernel.org/?p=linux/kernel/git/tiwai/sound-2.6.git;a=commit;h=4a122c10fbfe9020df469f0f669da129c5757671 upstream_linux: released (2.6.39~rc1) dapper_linux: DNE hardy_linux: not-affected lucid_linux: not-affected maverick_linux: released (2.6.35-30.52) natty_linux: released (2.6.38-8.40) devel_linux: not-affected (2.6.39-0.1) Patches_linux-ec2: upstream_linux-ec2: released (2.6.39~rc1) dapper_linux-ec2: DNE hardy_linux-ec2: DNE lucid_linux-ec2: not-affected maverick_linux-ec2: ignored (binary supplied by "linux" now) natty_linux-ec2: DNE devel_linux-ec2: DNE Patches_linux-mvl-dove: upstream_linux-mvl-dove: released (2.6.39~rc1) dapper_linux-mvl-dove: DNE hardy_linux-mvl-dove: DNE lucid_linux-mvl-dove: not-affected maverick_linux-mvl-dove: not-affected natty_linux-mvl-dove: DNE devel_linux-mvl-dove: DNE Patches_linux-ti-omap4: upstream_linux-ti-omap4: released (2.6.39~rc1) dapper_linux-ti-omap4: DNE hardy_linux-ti-omap4: DNE lucid_linux-ti-omap4: DNE maverick_linux-ti-omap4: released (2.6.35-903.23) natty_linux-ti-omap4: released (2.6.38-1208.11) devel_linux-ti-omap4: not-affected (2.6.38-1309.13) Patches_linux-lts-backport-maverick: upstream_linux-lts-backport-maverick: released (2.6.39~rc1) dapper_linux-lts-backport-maverick: DNE hardy_linux-lts-backport-maverick: DNE lucid_linux-lts-backport-maverick: released (2.6.35-30.54~lucid1) maverick_linux-lts-backport-maverick: DNE natty_linux-lts-backport-maverick: DNE devel_linux-lts-backport-maverick: DNE Patches_linux-fsl-imx51: upstream_linux-fsl-imx51: released (2.6.39~rc1) dapper_linux-fsl-imx51: DNE hardy_linux-fsl-imx51: DNE lucid_linux-fsl-imx51: not-affected maverick_linux-fsl-imx51: DNE natty_linux-fsl-imx51: DNE devel_linux-fsl-imx51: DNE Patches_linux-lts-backport-natty: upstream_linux-lts-backport-natty: released (2.6.39~rc1) hardy_linux-lts-backport-natty: DNE lucid_linux-lts-backport-natty: not-affected (2.6.38-8.40~lucid1) maverick_linux-lts-backport-natty: DNE natty_linux-lts-backport-natty: DNE devel_linux-lts-backport-natty: DNE