Impact
The vulnerability resides in the ALSA portman2x4 driver of the Linux kernel. When the driver probes a sound card, it checks the card index but does not guard against a negative value, which can be supplied as the special value “none” from sysfs. This omission allows an out-of-bounds read into the internal card index array and other parameters. An attacker able to supply such a value can read or corrupt kernel memory, potentially leading to denial of service or information disclosure. The weakness is a classic out-of-bounds read (CWE-125).
Affected Systems
This vulnerability affects the Linux kernel, specifically the unpatched ALSA portman2x4 driver. All Linux kernel versions shipping this driver without the fix are at risk until the patch is applied.
Risk and Exploitability
The CVSS score of 5.8 indicates a moderate rating. The EPSS score indicates a very low exploitation probability, less than 1%. KEV status is not listed, meaning no known exploits are recorded. Based on the description, it is inferred that the likely attack vector is local, requiring the ability to provoke the driver to probe a sound card with a negative index. An attacker could achieve this by loading the module or manipulating sysfs entries as described. Once the out-of-bounds read occurs, kernel memory corruption could lead to denial of service or information disclosure, making the risk significant for systems that load this driver.
OpenCVE Enrichment
Debian DSA