Impact
A bug in the Linux kernel’s ASoC SOF audio stack allowed the kernel to ignore failures from IPC time‑outs or firmware crashes and continue resetting the audio pipeline state incorrectly. The lack of proper error handling could leave the audio subsystem in an inconsistent or unusable state, potentially resulting in audio failures or kernel instability if the pipeline reset never completes.
Affected Systems
All Linux kernel builds that include the ASoC SOF ipc4‑pcm driver without the commit referenced in the advisory are potentially affected. The advisory does not list specific version numbers, so any kernel that implements the unpatched logic prior to the fix is considered at risk.
Risk and Exploitability
The CVSS score is 5.5, and the EPSS score is < 1%, indicating that the exploitation probability is low. The vulnerability is listed as not in the CISA KEV catalog. The most likely attack vector is local; an attacker would need to induce a firmware crash or create a scheduling blockage that triggers an IPC timeout. Because the conditions for exploitation are specific and not easily controllable remotely, the risk of exploitation is low at present.
OpenCVE Enrichment