Impact
The virmidi driver in the Linux kernel fails to validate the card index supplied via the sysfs interface, allowing a value of -1 to be used as a valid index. This oversight results in an out-of-bounds array access that can corrupt kernel memory or expose unintended data. The flaw is classified as CWE‑125 and can lead to kernel memory corruption or unintended information leakage.
Affected Systems
All Linux kernel builds that include the virmidi module prior to the patch are affected, meaning any system running the Linux kernel with the virmidi driver can potentially experience this issue until the kernel is upgraded to a version that implements the index sanity check.
Risk and Exploitability
The CVSS score of 4.7 indicates a low‑moderate severity. With an EPSS score of less than 1% and no listing in the CISA KEV catalogue, active exploitation is unlikely at present. An attacker would need local or privileged access to manipulate the sysfs interface and bind the device; the vulnerability does not provide a public remote attack vector.
OpenCVE Enrichment
Debian DSA