{"id":"CVE-2022-3170","details":"An out-of-bounds access issue was found in the Linux kernel sound subsystem. It could occur when the 'id-\u003ename' provided by the user did not end with '\\0'. A privileged local user could pass a specially crafted name through ioctl() interface and crash the system or potentially escalate their privileges on the system.","modified":"2026-08-12T03:51:22.889304008Z","published":"2022-09-13T15:36:36Z","database_specific":{"cna_assigner":"redhat","cwe_ids":["CWE-125"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/3xxx/CVE-2022-3170.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/3xxx/CVE-2022-3170.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-3170"},{"type":"FIX","url":"https://github.com/torvalds/linux/commit/5934d9a0383619c14df91af8fd76261dc3de2f5f"},{"type":"FIX","url":"https://github.com/torvalds/linux/commit/6ab55ec0a938c7f943a4edba3d6514f775983887"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/torvalds/linux","events":[{"introduced":"7e18e42e4b280c85b76967a9106a13ca61c16179"},{"last_affected":"7e18e42e4b280c85b76967a9106a13ca61c16179"}],"database_specific":{"extracted_events":[{"introduced":"fixed in kernel 6.0-rc4"},{"last_affected":"fixed in kernel 6.0-rc4"}],"source":"AFFECTED_FIELD"}}],"versions":["fixed in kernel 6.0-rc4","v6.0-rc4"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-3170.json"}}],"schema_version":"1.9.0"}