Impact
The ALSA pcxhr driver in the Linux kernel requests a threaded interrupt before initializing its manager mutex. Because the threaded handler acquires this mutex, an interrupt that occurs during driver probe can run with the mutex in an uninitialized state. This race condition leads to undefined behavior during driver initialization.
Affected Systems
All Linux kernels that ship the unpatched pcxhr ALSA driver are affected. The kernel source indicates the fix without specifying a particular version range, implying that any kernel older than the patch contains the issue. Since the ALSA subsystem is present across mainstream distributions, a wide array of systems may be vulnerable.
Risk and Exploitability
The CVSS score of 8.4 denotes high severity. The EPSS score of <1% indicates a very low but nonzero likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog, so no public exploits are known. The most probable attack vector requires a local or privileged attacker to trigger an interrupt while the driver is probing, such as by manipulating a PCI device.
OpenCVE Enrichment
Debian DSA