FlawAtlas
Search the atlas
UBUNTU-CVE-2017-1000380 Moderate

UBUNTU-CVE-2017-1000380

sound/core/timer.c in the Linux kernel before 4.11.5 is vulnerable to a data race in the ALSA /dev/snd/timer driver resulting in local users being able to read information belonging to other users, i.e., uninitialized memory contents may be disclosed when a read and an ioctl happen at the same time.

Exploit probability Not scored
Published June 17, 2017
Required by Not available
Last source change August 17, 2026

02 / AFFECTED SOFTWARE

Affected packages

Ubuntu:14.04:LTS linux

116 explicit affected versions

Ubuntu:14.04:LTS linux-lts-xenial

33 explicit affected versions

Ubuntu:16.04:LTS linux

55 explicit affected versions

Ubuntu:16.04:LTS linux-aws

13 explicit affected versions

Ubuntu:16.04:LTS linux-gke

11 explicit affected versions

Ubuntu:16.04:LTS linux-hwe

17 explicit affected versions

Ubuntu:16.04:LTS linux-raspi2

31 explicit affected versions

Ubuntu:16.04:LTS linux-snapdragon

28 explicit affected versions

Ubuntu:20.04:LTS linux-azure-fde

26 explicit affected versions

Ubuntu:20.04:LTS linux-gke

51 explicit affected versions

Ubuntu:20.04:LTS linux-raspi2

6 explicit affected versions

Ubuntu:20.04:LTS linux-riscv

12 explicit affected versions

Ubuntu:22.04:LTS linux-intel-iot-realtime

1 explicit affected versions

Ubuntu:22.04:LTS linux-realtime

1 explicit affected versions

Ubuntu:22.04:LTS linux-riscv

23 explicit affected versions

Ubuntu:24.04:LTS linux-azure-6.11

7 explicit affected versions

Ubuntu:24.04:LTS linux-gcp-6.11

7 explicit affected versions

Ubuntu:24.04:LTS linux-hwe-6.11

8 explicit affected versions

Ubuntu:24.04:LTS linux-lowlatency-hwe-6.11

7 explicit affected versions

Ubuntu:24.04:LTS linux-raspi-realtime

1 explicit affected versions

Ubuntu:Pro:20.04:LTS linux-azure-fde-5.15

61 explicit affected versions

03 / CONNECTIONS

Connected vulnerabilities

related USN-3358-1
related USN-3359-1
related USN-3360-2

04 / EVIDENCE

Source records

Open Source Vulnerabilities UBUNTU-CVE-2017-1000380

sound/core/timer.c in the Linux kernel before 4.11.5 is vulnerable to a data race in the ALSA /dev/snd/timer driver resulting in local users being able to read information belonging to other users, i.e., uninitialized memory contents may be disclosed when a read and an ioctl happen at the same time.

View original source

05 / REFERENCES

Further evidence