Multiple buffer overflows in the caiaq Native Instruments USB audio functionality in the Linux kernel before 2.6.38-rc4-next-20110215 might allow attackers to cause a denial of service or possibly have unspecified other impact via a long USB device name, related to (1) the snd_usb_caiaq_audio_init function in sound/usb/caiaq/audio.c and (2) the snd_usb_caiaq_midi_init function in sound/usb/caiaq/midi.c.
Threat-Mapped Scoring
Score: 1.5
Priority: P4 - Informational (Low)
S10 – Denial of Service
EPSS
Score: 0.00056 Percentile:
0.17586
CVSS Scoring
CVSS v2 Score: 7.2
Severity:
Mapped CWE(s)
CWE-120
: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
All CAPEC(s)
CAPEC-10: Buffer Overflow via Environment Variables