CVE-2014-9904: Debian Linux

High severity, CVSS 7.8. EPSS: 0.4% chance of exploitation in the next 30 days.

The snd_compress_check_input function in sound/core/compress_offload.c in the ALSA subsystem in the Linux kernel before 3.17 does not properly check for an integer overflow, which allows local users to cause a denial of service (insufficient memory allocation) or possibly have unspecified other impact via a crafted SNDRV_COMPRESS_SET_PARAMS ioctl call.

Affected products

  • Debian Debian Linux: version 8.0 only
  • Linux Linux Kernel: from 3.7, before 3.12.62 (fixed in 3.12.62); from 3.13, before 3.16.37 (fixed in 3.16.37)
  • Novell Suse Linux Enterprise Real Time Extension: version 12 only

Published 2016-06-27. Last modified 2026-06-17.