Impact
A size‑check bug in the Linux kernel’s ASoC SDCA UMP message handling allows a message offset that exceeds the allocated buffer length to pass the validation incorrectly. Based on the description, this can lead to memory corruption in kernel space, potentially enabling a local attacker to obtain higher privileges or execute arbitrary code with kernel rights.
Affected Systems
All Linux kernel releases that contain the vulnerable code path are affected. The patch that fixes the issue is embodied in the commit 556d872e7c2a0b570c5b0974813847ef0d0cd637. Any kernel build prior to the inclusion of this commit is considered vulnerable until an update is applied.
Risk and Exploitability
The EPSS score is not available and the vulnerability is not listed in CISA KEV, indicating no known widespread exploitation yet. However, the flaw is a local memory‑safety violation that can be triggered by sending crafted SDCA/UMP messages. The lack of a CVSS score prevents precise severity quantification, but the potential for privilege escalation and kernel corruption warrants timely remediation.
OpenCVE Enrichment