Impact
A flaw in the Linux kernel’s advanced sound architecture for Meson AIU HDMI and internal codec mux drivers causes the system to convert an enumeration value to a numeric representation before verifying its validity. The unchecked conversion can lead the kernel to process an out‑of‑range value, potentially corrupting memory or causing undefined kernel behavior. Based on the description, the issue appears to require access to the AIU HDMI or internal codec mux controls, so an attacker would need local write capabilities to the relevant device interfaces.
Affected Systems
All Linux kernel builds that contain the unpatched ASoC Meson AIU HDMI and internal codec mux callback code. Because no specific version numbers are disclosed, any kernel compiled before the corrective commit is potentially affected.
Risk and Exploitability
The EPSS score is less than 1% and the vulnerability is not listed in CISA’s KEV catalog, indicating a historically low likelihood of exploitation. However, the CVSS score of 7.3 reflects a high severity for a kernel memory corruption condition. The attack vector is likely local; a process with the ability to write to the AIU HDMI or internal codec mux device nodes could trigger the flaw, leading to kernel instability or privilege escalation if memory corruption propagates. The overall risk remains moderate to high until the patch is applied.
OpenCVE Enrichment