Unrated severityNVD Advisory· Published Jan 13, 2011· Updated Jun 16, 2026
CVE-2010-4527
CVE-2010-4527
Description
The load_mixer_volumes function in sound/oss/soundcard.c in the OSS sound subsystem in the Linux kernel before 2.6.37 incorrectly expects that a certain name field ends with a '\0' character, which allows local users to conduct buffer overflow attacks and gain privileges, or possibly obtain sensitive information from kernel memory, via a SOUND_MIXER_SETLEVELS ioctl call.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2- Range: <2.6.37
Patches
Vulnerability mechanics
References
11- openwall.com/lists/oss-security/2010/12/31/1nvdMailing ListPatchThird Party Advisory
- bugzilla.redhat.com/show_bug.cginvdIssue TrackingPatchThird Party Advisory
- xorl.wordpress.com/2011/01/09/cve-2010-4527-linux-kernel-oss-sound-card-driver-buffer-overflow/nvdExploitThird Party Advisory
- lists.opensuse.org/opensuse-security-announce/2011-02/msg00002.htmlnvdMailing ListThird Party Advisory
- openwall.com/lists/oss-security/2010/12/31/4nvdMailing ListThird Party Advisory
- secunia.com/advisories/42765nvdThird Party Advisory
- secunia.com/advisories/43291nvdThird Party Advisory
- www.securityfocus.com/bid/45629nvdThird Party AdvisoryVDB Entry
- www.vupen.com/english/advisories/2011/0375nvdThird Party Advisory
- www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.37nvdBroken Link
- git.kernel.orgnvd
News mentions
0No linked articles in our index yet.