Impact
During the probe of the ALSA mts64 driver, the driver performs a check on the devptr->id value but does not validate negative values. When a negative id is set via sysfs (for example, the string "none"), the driver may access index[] and other parameters outside their intended bounds. This out-of-bounds access could corrupt adjacent memory structures. Based on the description, this could lead to unintended modification of kernel memory, potentially causing driver failures or broader system instability when the issue is triggered. The vulnerability arises from unchecked input in the ALSA mts64 driver, allowing negative identifiers to be passed from sysfs to the probe routine.
Affected Systems
All Linux kernel versions that ship the ALSA mts64 driver without the patch are affected. Systems using those kernels and having a mts64-compatible audio device exposed through sysfs are potentially vulnerable. No.
Risk and Exploitability
The CVSS score of 4.7 indicates moderate risk while the EPSS score of < 1% suggests a low probability of exploitation under typical conditions. It is not listed in the likely local: an attacker would need permission to write to sysfs entries for the sound subsystem or otherwise trigger the probe routine. Successful exploitation could result in driver failure or, if memory corruption occurs, unspecified effects. The vulnerability does not appear to be exploitable over a network.
OpenCVE Enrichment
Debian DSA