CVE-2011-1169

Description

From CVE.org

Array index error in the asihpi_hpi_ioctl function in sound/pci/asihpi/hpioctl.c in the AudioScience HPI driver in the Linux kernel before 2.6.38.1 might allow local users to cause a denial of service (memory corruption) or possibly gain privileges via a crafted adapter index value that triggers access to an invalid kernel pointer.

Statement

The Linux kernel as shipped with Red Hat Enterprise Linux 4, 5, 6 and Red Hat Enterprise MRG are not affected as they did not backport upstream commit 719f82d3 that introduced this issue.

Acknowledgements

Red Hat would like to thank Dan Rosenberg for reporting this issue.

Frequently Asked Questions

Want to get errata notifications? Sign up here.