High severity7.8NVD Advisory· Published Jun 27, 2016· Updated Jun 17, 2026
CVE-2014-9904
CVE-2014-9904
Description
The snd_compress_check_input function in sound/core/compress_offload.c in the ALSA subsystem in the Linux kernel before 3.17 does not properly check for an integer overflow, which allows local users to cause a denial of service (insufficient memory allocation) or possibly have unspecified other impact via a crafted SNDRV_COMPRESS_SET_PARAMS ioctl call.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
37- cpe:2.3:o:novell:suse_linux_enterprise_real_time_extension:12:sp1:*:*:*:*:*:*
- osv-coords33 versionspkg:rpm/suse/kernel-compute_debug&distro=SUSE%20Linux%20Enterprise%20Real%20Time%2012%20SP1pkg:rpm/suse/kernel-compute&distro=SUSE%20Linux%20Enterprise%20Real%20Time%2012%20SP1pkg:rpm/suse/kernel-default&distro=SUSE%20Linux%20Enterprise%20Desktop%2012%20SP1pkg:rpm/suse/kernel-default&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP1pkg:rpm/suse/kernel-default&distro=SUSE%20Linux%20Enterprise%20Server%2012-LTSSpkg:rpm/suse/kernel-default&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012pkg:rpm/suse/kernel-default&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP1pkg:rpm/suse/kernel-default&distro=SUSE%20Linux%20Enterprise%20Workstation%20Extension%2012%20SP1pkg:rpm/suse/kernel-docs&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP1pkg:rpm/suse/kernel-ec2&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Public%20Cloud%2012pkg:rpm/suse/kernel-obs-build&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP1pkg:rpm/suse/kernel-rt_debug&distro=SUSE%20Linux%20Enterprise%20Real%20Time%2012%20SP1pkg:rpm/suse/kernel-rt&distro=SUSE%20Linux%20Enterprise%20Real%20Time%2012%20SP1pkg:rpm/suse/kernel-source&distro=SUSE%20Linux%20Enterprise%20Desktop%2012%20SP1pkg:rpm/suse/kernel-source&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP1pkg:rpm/suse/kernel-source&distro=SUSE%20Linux%20Enterprise%20Server%2012-LTSSpkg:rpm/suse/kernel-source&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012pkg:rpm/suse/kernel-source&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP1pkg:rpm/suse/kernel-source-rt&distro=SUSE%20Linux%20Enterprise%20Real%20Time%2012%20SP1pkg:rpm/suse/kernel-syms&distro=SUSE%20Linux%20Enterprise%20Desktop%2012%20SP1pkg:rpm/suse/kernel-syms&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP1pkg:rpm/suse/kernel-syms&distro=SUSE%20Linux%20Enterprise%20Server%2012-LTSSpkg:rpm/suse/kernel-syms&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012pkg:rpm/suse/kernel-syms&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP1pkg:rpm/suse/kernel-syms-rt&distro=SUSE%20Linux%20Enterprise%20Real%20Time%2012%20SP1pkg:rpm/suse/kernel-xen&distro=SUSE%20Linux%20Enterprise%20Desktop%2012%20SP1pkg:rpm/suse/kernel-xen&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP1pkg:rpm/suse/kernel-xen&distro=SUSE%20Linux%20Enterprise%20Server%2012-LTSSpkg:rpm/suse/kernel-xen&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012pkg:rpm/suse/kernel-xen&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP1pkg:rpm/suse/kgraft-patch-SLE12-SP1_Update_7&distro=SUSE%20Linux%20Enterprise%20Live%20Patching%2012pkg:rpm/suse/kgraft-patch-SLE12_Update_19&distro=SUSE%20Linux%20Enterprise%20Server%2012-LTSSpkg:rpm/suse/kgraft-patch-SLE12_Update_19&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012
< 3.12.61-60.18.1+ 32 more
- (no CPE)range: < 3.12.61-60.18.1
- (no CPE)range: < 3.12.61-60.18.1
- (no CPE)range: < 3.12.62-60.62.1
- (no CPE)range: < 3.12.62-60.62.1
- (no CPE)range: < 3.12.61-52.66.1
- (no CPE)range: < 3.12.61-52.66.1
- (no CPE)range: < 3.12.62-60.62.1
- (no CPE)range: < 3.12.62-60.62.1
- (no CPE)range: < 3.12.62-60.62.3
- (no CPE)range: < 3.12.62-60.62.1
- (no CPE)range: < 3.12.62-60.62.1
- (no CPE)range: < 3.12.61-60.18.1
- (no CPE)range: < 3.12.61-60.18.1
- (no CPE)range: < 3.12.62-60.62.1
- (no CPE)range: < 3.12.62-60.62.1
- (no CPE)range: < 3.12.61-52.66.1
- (no CPE)range: < 3.12.61-52.66.1
- (no CPE)range: < 3.12.62-60.62.1
- (no CPE)range: < 3.12.61-60.18.1
- (no CPE)range: < 3.12.62-60.62.1
- (no CPE)range: < 3.12.62-60.62.1
- (no CPE)range: < 3.12.61-52.66.1
- (no CPE)range: < 3.12.61-52.66.1
- (no CPE)range: < 3.12.62-60.62.1
- (no CPE)range: < 3.12.61-60.18.1
- (no CPE)range: < 3.12.62-60.62.1
- (no CPE)range: < 3.12.62-60.62.1
- (no CPE)range: < 3.12.61-52.66.1
- (no CPE)range: < 3.12.61-52.66.1
- (no CPE)range: < 3.12.62-60.62.1
- (no CPE)range: < 1-4.2
- (no CPE)range: < 1-2.1
- (no CPE)range: < 1-2.1
Patches
Vulnerability mechanics
References
8- git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/nvdPatchVendor Advisory
- github.com/torvalds/linux/commit/6217e5ede23285ddfee10d2e4ba0cc2d4c046205nvdPatchVendor Advisory
- lists.opensuse.org/opensuse-security-announce/2016-08/msg00000.htmlnvdThird Party Advisory
- lists.opensuse.org/opensuse-security-announce/2016-08/msg00044.htmlnvdMailing ListThird Party Advisory
- lists.opensuse.org/opensuse-security-announce/2016-08/msg00055.htmlnvdMailing ListThird Party Advisory
- www.debian.org/security/2016/dsa-3616nvdThird Party Advisory
- www.securityfocus.com/bid/91510nvdThird Party AdvisoryVDB Entry
- www.securitytracker.com/id/1036189nvdThird Party AdvisoryVDB Entry
News mentions
0No linked articles in our index yet.