Impact
During a system resume, failures in the ALSA USB audio resume path caused the driver to skip critical cleanup steps. The device remained in a powered-down state and control access was blocked, resulting in the audio device becoming unusable until a reboot. The flaw illustrates improper resource shutdown (CWE-668).
Affected Systems
All Linux kernel releases containing the ALSA USB audio driver before the introduction of the referenced commits are affected. The issue applies to every kernel that supports USB audio devices through the ALSA subsystem and does not require any third‑party code.
Risk and Exploitability
The CVSS score is not listed, and EPSS is not available, so the exploitation probability cannot be quantified. The vulnerability is not present in the CISA KEV list. The most likely attack vector is a local privileged user or kernel attacker able to force a system suspend and resume cycle while a faulty USB audio device is attached. By repeatedly inducing the error path the device can be rendered permanently inoperable until a system reboot, effectively causing a denial‑of‑service. No known public exploits have been reported, and the fix can only be applied by patching the kernel.
OpenCVE Enrichment