Impact
In the Linux kernel ALSA FCP handler, an ioctl operation allocates a response buffer that is never initialized before copying it back to user space. The driver accepts a short or zero‑length USB control transfer, which the kernel then retains in the allocated slab. An attacker can thus read kernel memory contents, including addresses, leaking sensitive information. Based on the description, it is inferred that an attacker who can trigger the ioctl can read kernel memory, resulting in information disclosure.
Affected Systems
The Linux kernel is the affected patch is vulnerable. Distributions that have not applied the fix remain exposed even if they are recent official releases.
Risk and Exploitability
The CVSS score of 4.5 indicates a low severity, the EPSS score is < 1%, and the vulnerability is not listed in KEV, suggesting a low exploitation probability. Based on the description, it is inferred that an attacker can trigger the ioctl from a local user interacting with a USB audio device; the likely attack vector is a local user interacting with a malicious or misbehaving USB audio device that triggers the ALSA FCP ioctl, with the attacker gaining read access to kernel memory through the uninitialized buffer copy.
OpenCVE Enrichment