[SRU Bionic 0/1] CVE-2022-3303

Cengiz Can cengiz.can at canonical.com
Wed May 24 07:17:19 UTC 2023


[Impact]
It was discovered that the sound subsystem in the Linux kernel contained a race
condition in some situations. A local attacker could use this to cause a denial
of service (system crash).

[Fix]
Cherry picked from linux-5.4.y. Upstream fix does not apply due to error
checking differences.

[Test case]
Compile and boot tested only.

[Potential regression]
Low. Moves an error check a little bit further.

Sasha Levin (1):
  ALSA: pcm: oss: Fix race at SNDCTL_DSP_SYNC

 sound/core/oss/pcm_oss.c | 5 +++--
 1 file changed, 3 insertions(+), 2 deletions(-)

-- 
2.39.2




More information about the kernel-team mailing list