Impact
The ALSA mpu401 driver in the Linux kernel assumes the device pointer’s id field is always a valid index during probe. When a driver is manually bound through the sysfs interface, the id may be set to –1 to indicate ‘none’, which causes the driver to access an array outside its bounds, potentially corrupting memory or crashing the kernel. This flaw is a classic out‑of-bounds read (CWE‑125) and does not directly result in code execution but can destabilize the system or leak sensitive data.
Affected Systems
All Linux kernel builds that include the unpatched mpu401 ALSA driver, including default distributions and custom in‑tree kernels, are affected until the fix that checks the card index and corrects invalid values is applied.
Risk and Exploitability
The CVSS score of 4.1 classifies the vulnerability as low severity, and the EPSS score of less than 1 % indicates a low probability of exploitation. It is not listed in the CISA KEV catalog. The exploit requires local file system write access to the sysfs binding interface, making the attack vector local. An attacker with such privileges can trigger the out‑of‑bounds read, potentially causing a denial of service or accessing kernel memory.
OpenCVE Enrichment
Debian DSA