Impact
The MT8192 audio firmware driver in the Linux kernel fails to release reserved memory when the probe fails or when the driver is unbound. The unreleased memory can accumulate and exhaust kernel space, potentially preventing allocation of new buffers. This resource exhaustion can lead to system instability or denial of service.
Affected Systems
The flaw is present in the Linux kernel's Media Audio Subsystem (ASoC) driver for Mediatek MT8192. It affects any kernel build containing the mediatek mt8192 AFE probe; no specific kernel versions are listed, so the vulnerability applies until the fix is applied.
Risk and Exploitability
The EPSS score is < 1% and the CVSS score is 5.5, and the KEV database does not list this CVE, indicating no known exploited instances. The attack likely requires local or kernel-level privilege to load or probe the media driver, which suggests a local attacker could trigger repeated probe failures and consume memory. In the absence of a known exploit, the risk is principally the potential for a denial‑of‑service condition if memory becomes exhausted.
OpenCVE Enrichment