Bugzilla – Bug 1169384
VUL-1: CVE-2020-11725: kernel-source: improper handling in the private_size*count multiplication due to count=info->owner typo
Last modified: 2020-12-21 11:43:12 UTC
CVE-2020-11725 snd_ctl_elem_add in sound/core/control.c in the Linux kernel through 5.6.3 has a count=info->owner typo, which is mishandled in the private_size*count multiplication. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2020-11725 http://people.canonical.com/~ubuntu-security/cve/2020/CVE-2020-11725.html https://github.com/torvalds/linux/blob/3b2549a3740efb8af0150415737067d87e466c5b/sound/core/control.c#L1434-L1474 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-11725 https://twitter.com/yabbadabbadrew/status/1248632267028582400
will dispute following Takashi's response at [1] [1] https://lore.kernel.org/alsa-devel/s5h4ktmlfpx.wl-tiwai@suse.de/
Thanks! Reassigning back to security team.
Disputed. Closing