Impact
The ALSA ctxfi driver failed to handle the SPDIF1 DAIO type correctly, causing daio_device_index() to return an erroneous index for hw20k2. This caused an out‐of‐bounds array access, which can corrupt kernel memory. The corruption may lead to a system crash or other instability effects. This is a Buffer Access with Incorrect Index (CWE‑1285) and also maps to CWE‑129.
Affected Systems
All Linux kernel builds that contain the ALSA ctxfi driver and have not been patched for this issue are affected. No specific kernel release numbers are listed in the available data.
Risk and Exploitability
The vulnerability has a CVSS score of 7.8 and an EPSS score of < 1%, indicating a very low probability of exploitation. It is not listed in the CISA KEV catalog. As an out-of-bounds array access in kernel space, the exploit is likely to require local access and may lead to kernel memory corruption, potentially causing a system crash or denial of service.
OpenCVE Enrichment
Debian DLA
Debian DSA