VYPR
High severity7.8NVD Advisory· Published Sep 13, 2022· Updated Jun 17, 2026

CVE-2022-3170

CVE-2022-3170

Description

An out-of-bounds access issue was found in the Linux kernel sound subsystem. It could occur when the 'id->name' provided by the user did not end with '\0'. A privileged local user could pass a specially crafted name through ioctl() interface and crash the system or potentially escalate their privileges on the system.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

5
  • Linux/Kernel4 versions
    cpe:2.3:o:linux:linux_kernel:6.0:rc1:*:*:*:*:*:*+ 3 more
    • cpe:2.3:o:linux:linux_kernel:6.0:rc1:*:*:*:*:*:*
    • cpe:2.3:o:linux:linux_kernel:6.0:rc2:*:*:*:*:*:*
    • cpe:2.3:o:linux:linux_kernel:6.0:rc3:*:*:*:*:*:*
    • (no CPE)
  • Linux/Linux kernel sound subsystemdescription

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.