APPLIED: [SRU][J/K][PATCH 0/1] CVE-2023-0266

Luke Nowakowski-Krijger luke.nowakowskikrijger at canonical.com
Thu Feb 16 21:57:34 UTC 2023


Applied to jammy, kinetic linux master-next

Thanks,
- Luke

On Tue, Feb 14, 2023 at 3:57 PM Yuxuan Luo <yuxuan.luo at canonical.com> wrote:

> [Impact]
> There exists a vulnerability triggering trace in ALSA PCM package for
> specifically 32-bit machines which consequences in calling a sequence
> sensitive
> function without a lock. This issue may lead to a use-after-free that
> results
> in a priviledge escalation.
>
> [Backport]
> Clean cherry pick on both releases.
>
> [Test]
> Compile and smoke tested.
>
> [Potential Regression]
> Potential regression resides in `control.c` and `control_compat.c` files
> with
> likely low risk.
>
> Clement Lecigne (1):
>   ALSA: pcm: Move rwsem lock inside snd_ctl_elem_read to prevent UAF
>
>  sound/core/control.c | 24 +++++++++++++++---------
>  1 file changed, 15 insertions(+), 9 deletions(-)
>
> --
> 2.34.1
>
>
> --
> kernel-team mailing list
> kernel-team at lists.ubuntu.com
> https://lists.ubuntu.com/mailman/listinfo/kernel-team
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.ubuntu.com/archives/kernel-team/attachments/20230216/b08b0a52/attachment.html>


More information about the kernel-team mailing list