Back to Database
Status published
High
CVE-2017-0861
Use-after-free vulnerability in the snd_pcm_info function in the ALSA subsystem...
Vulnerability Description
Use-after-free vulnerability in the snd_pcm_info function in the ALSA subsystem in the Linux kernel allows attackers to gain privileges via unspecified vectors.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2017-0861
Credits & Attribution
No credits recorded in the NVD database.
References
- https://access.redhat.com/errata/RHSA-2018:3083
- https://www.debian.org/security/2018/dsa-4187
- https://usn.ubuntu.com/3617-1/
- https://usn.ubuntu.com/3619-2/
- https://usn.ubuntu.com/3617-3/
- https://usn.ubuntu.com/3583-2/
- https://usn.ubuntu.com/3632-1/
- https://access.redhat.com/errata/RHSA-2018:2390
- https://usn.ubuntu.com/3583-1/
- http://lists.alioth.debian.org/pipermail/secure-testing-commits/2017-December/059967.html
- https://lists.debian.org/debian-lts-announce/2018/05/msg00000.html
- https://usn.ubuntu.com/3617-2/
- https://access.redhat.com/errata/RHSA-2018:3096
- https://usn.ubuntu.com/3619-1/
- http://www.securityfocus.com/bid/102329
- https://access.redhat.com/errata/RHSA-2020:0036
- https://www.oracle.com/security-alerts/cpujul2020.html
- https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html
- https://help.ecostruxureit.com/display/public/UADCE725/Security+fixes+in+StruxureWare+Data+Center+Expert+v7.6.0
- https://source.android.com/security/bulletin/pixel/2017-11-01
- https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=362bca57f5d78220f8b5907b875961af9436e229
- https://security-tracker.debian.org/tracker/CVE-2017-0861
More from Google Inc.
View All →CVE-2018-9580
A Elevation of privilege vulnerability in the HTC bootloader. Product:...
Critical
9.8
CVE-2018-9578
In ixheaacd_adts_crc_start_reg of ixheaacd_adts_crc_check.c, there is a possible out of...
Critical
9.8
CVE-2018-9577
In impd_parametric_drc_parse_gain_set_params of impd_drc_static_payload.c there is a possible out of...
High
7.8
CVE-2018-9576
In impd_parse_parametric_drc_instructions of impd_drc_static_payload.c there is a possible out of...
High
7.8
CVE-2018-9575
In impd_parse_dwnmix_instructions of impd_drc_static_payload.c there is a possible out of...
High
7.8
Affected Vendor
Google Inc.
View all reports →Affected Software
Android
Vulnerable Versions:
Android kernel
Timeline
Official Publish:
November 16th, 2017
Last Modified:
September 16th, 2024
Added to House:
July 20th, 2026
CVSS Vectors
V3:
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.