Impact
The flaw causes the ALSA hda cs35l41 driver to keep an ACPI _DSM object in memory without freeing it, creating a memory leak. The driver also assumes the returned object is a non‑empty buffer; a malformed response can cause the driver to dereference an invalid pointer. The result is kernel memory that can be read by a local attacker or a kernel crash that could lead to a denial of service.
Affected Systems
All Linux kernels that compile the ALSA hda cs35l41 driver are affected. The vulnerability exists in any kernel release containing the unpatched code for that device, regardless of distribution or version tags. Thus any system running a supported kernel with the driver enabled is at risk.
Risk and Exploitability
The CVSS score of 5.5 indicates moderate severity, and the EPSS score of <1% suggests a low likelihood of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. An attacker would need local access that allows the cs35l41 driver to issue an ACPI _DSM call, for example by interacting with the hardware or loading the driver. Because the fault occurs in kernel space, exploitation could lead to a local privilege escalation via a kernel panic or leakage of kernel memory contents. No public exploit is known, but the moderate score reflects the potential for denial of service and information disclosure with local privileges.
OpenCVE Enrichment
Debian DLA