Impact
The ALSA serial‑u16550 driver in the Linux kernel does not validate the device identifier supplied through the sysfs binding interface. As a result, an out‑of‑bounds array access into the driver’s internal card index array can occur when the device is bound manually. The advisory states that this can lead to out‑of‑bounds memory access, but it does not explicitly describe the downstream effects such as kernel crash or data leakage. Based on the nature of the flaw, it is inferred that memory corruption could happen, but the exact impact is not confirmed in the provided information.
Affected Systems
All Linux distributions that ship a standard Linux kernel and enable the serial‑u16550 module are affected. No specific distribution or kernel version is excluded in the provided data.
Risk and Exploitability
The CVSS score of 4.1 reflects medium severity, while the EPSS score of exploitation probability is less than 1%. The vulnerability is not listed in CISA’s KEV catalog. An attacker must have local access to modify the sysfs binding of the device; no remote exploitation path is documented.
OpenCVE Enrichment
Debian DSA