Bugzilla – Bug 992731
VUL-1: CVE-2014-9892: kernel: snd_compr_tstamp through 4.7 infoleak
Last modified: 2016-08-10 12:25:18 UTC
CVE-2014-9892 References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2014-9892 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-9892
It doesn't hit to any already released products. Only TW, SLE12-SP2 and openSUSE-42.2 kernels enable CONFIG_SND_COMPRESS_OFFLOAD.
And the issue has been fixed in upstream by commit 17ac8e5c6d3478dcfeb75ed5716ca7e5cee612f0 ALSA: core: don't return uninitialized snd_compr_tstamp which is included in 3.9 kernel. So all our products are fine.
Reassigned back to security team.
Thanks, closing as INVALID.