Array index error in the asihpi_hpi_ioctl function in sound/pci/asihpi/hpioctl.c in the AudioScience HPI driver in the Linux kernel before 2.6.38.1 might allow local users to cause a denial of service (memory corruption) or possibly gain privileges via a crafted adapter index value that triggers access to an invalid kernel pointer.
The product uses untrusted input when calculating or using an array index, but the product does not validate or incorrectly validates the index to ensure the index references a valid position within the array.
Link | Tags |
---|---|
https://bugzilla.redhat.com/show_bug.cgi?id=688898 | issue tracking third party advisory patch |
http://openwall.com/lists/oss-security/2011/03/18/1 | third party advisory mailing list |
http://git.kernel.org/?p=linux/kernel/git/tiwai/sound-2.6.git%3Ba=commit%3Bh=4a122c10fbfe9020df469f0f669da129c5757671 | |
http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.38.1 | release notes vendor advisory |
http://openwall.com/lists/oss-security/2011/03/18/2 | third party advisory mailing list |