** Changed in: linux-snapdragon (Ubuntu Precise) Status: New => Invalid
** Changed in: linux-snapdragon (Ubuntu Precise) Importance: Undecided => Medium ** Changed in: linux-snapdragon (Ubuntu Wily) Status: New => Invalid ** Changed in: linux-snapdragon (Ubuntu Wily) Importance: Undecided => Medium ** Changed in: linux-snapdragon (Ubuntu Xenial) Status: New => Invalid ** Changed in: linux-snapdragon (Ubuntu Xenial) Importance: Undecided => Medium ** Changed in: linux-snapdragon (Ubuntu Yakkety) Status: New => Invalid ** Changed in: linux-snapdragon (Ubuntu Yakkety) Importance: Undecided => Medium ** Changed in: linux-snapdragon (Ubuntu Trusty) Status: New => Invalid ** Changed in: linux-snapdragon (Ubuntu Trusty) Importance: Undecided => Medium ** Description changed: - ALSA sequencer code has an open race between the timer setup ioctl and - the close of the client. This was triggered by syzkaller fuzzer, and a - use-after-free was caught there as a result. + Race condition in the queue_delete function in + sound/core/seq/seq_queue.c in the Linux kernel before 4.4.1 allows local + users to cause a denial of service (use-after-free and system crash) by + making an ioctl call at a certain time. Break-Fix: - 3567eb6af614dac436c4b16a8d426f9faed639b3 -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1549182 Title: CVE-2016-2544 To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/linux/+bug/1549182/+subscriptions -- ubuntu-bugs mailing list ubuntu-bugs@lists.ubuntu.com https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs