CVE-2012-6703 describes an integer overflow vulnerability in the ALSA subsystem of the Linux kernel before version 3.6-rc6-next-20120917. This flaw, specifically within the snd_compr_allocate_buffer function, allows a local attacker to trigger a denial of service through insufficient memory allocation, or potentially achieve other unspecified impacts, by sending a specially crafted SNDRV_COMPRESS_SET_PARAMS ioctl call. With a CVSS v3.1 score of 7.8 (High), this vulnerability has a low attack complexity and requires local user privileges, but can lead to high impacts on confidentiality, integrity, and availability. Despite its high severity, there is no evidence of active exploitation, and no public exploit code is available in Metasploit, Nuclei, or ExploitDB. Furthermore, the CVE has garnered minimal community discussion or media coverage, indicating a low level of public attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 3.3, < 3.7CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.