Impact
A buffer overread can occur in the ALSA 6fire driver when a connected USB 6fire device supplies a MIDI event length larger than the 64‑byte receive buffer. The driver copies the length byte sent, 255 bytes starting two bytes into the 64‑byte buffer. This classic out‑of‑bounds read (CWE‑125) allows kernel memory to be exposed through the raw‑MIDI read path, providing an information‑disclosure vector.
Affected Systems
All systems running a Linux kernel that contains the ALSA 6fire driver before the vendor patch, regardless of distribution or architecture, are affected. The fix was made in the internal patch series referenced in the kernel tree and is expected to be present in subsequent kernel releases.
Risk and Exploitability
The CVSS score of 6.3 indicates moderate severity, while the EPSS score is under 1%, showing a very low likelihood of widespread exploitation. The flaw is not listed in the CISA KEV catalog. The attacker must supply a USB physically, and the vulnerability triggers automatically on plug‑in before any user action is needed. No publicly known exploit exists, but the kernel memory read could be a stepping‑stone for more advanced attacks if additional privileges can be obtained.
OpenCVE Enrichment
Debian DSA