Impact
In the Linux kernel, the aloop driver blindly trusts the devptr->id value provided during probe, assuming it is a valid card index. When a device is bound manually via the sysfs interface, that value can be –1 to indicate “none”, which leads to an out‑of‑bounds memory access for the index array and related parameters. This flaw can corrupt kernel memory, potentially allowing an attacker to trigger the unsafe probe path and compromise the system.
Affected Systems
Linux kernel driver is impacted. The issue is present in all kernel versions that include the aloop driver without the sanity check; no specific kernel release or version string was supplied by the CNA. Any system running a Linux kernel with ALSA support is therefore at risk when the sysfs binding mechanism is used.
Risk and Exploitability
The flaw requires local access to the sysfs interface to bind a device manually and provoke the out‑of‑bounds access. The EPSS score is < 1%, indicating a very low probability of widespread exploitation. The kernel may become unstable or an attacker may gain higher privileges, but the attack surface is limited to users with write access to the ALSA sysfs paths. The vulnerability is not listed in CISA's KEV catalog.
OpenCVE Enrichment
Debian DSA