Impact
The ALSA ctxfi driver failed to handle the SPDIF1 DAIO type correctly, causing daio_device_index() to return an erroneous index for hw20k2. This caused an out‑of‑bounds array access, which can corrupt kernel memory. The corruption may lead to a system crash or provide a local attacker with the ability to execute code at elevated privileges, resulting in denial of service or privilege escalation.
Affected Systems
All Linux kernel builds that contain the ALSA ctxfi driver and have not been patched for this issue are affected. No specific kernel release numbers are listed in the available data.
Risk and Exploitability
The vulnerability does not have an associated CVSS score or EPSS information, and it is not listed in the CISA KEV catalog. As an out‑of‑bounds array access in kernel space, the exploit is likely to require local access and, in the worst case, could allow a local attacker to gain root privileges or cause a denial of service. The lack of public exploitation data suggests the risk is moderate, but the severity of potential memory corruption warrants prompt remediation.
OpenCVE Enrichment
Debian DLA
Debian DSA