Impact
The u_audio USB gadget driver contains a use‑after‑free flaw (CWE‑825). When a sound card is disconnected while a userspace ALSA control element remains open, the driver before all ALSA references are released. Subsequent callbacks then dereference memorying kernel data and potentially allowing an attacker to execute arbitrary code with kernel privileges.
Affected Systems
All Linux kernel builds that include the u_audio gadget driver are affected. The vulnerability applies to both default kernel configurations and custom builds that enable the driver, whether it is compiled into the kernel or loaded as a module.
Risk and Exploitability
The vulnerability’s CVSS score of 7.8 indicates moderate to high severity. The EPSS of less than 1 % suggests a low current exploitation likelihood, and the flaw is not listed in CISA’s KEV catalog. Exploitation requires a local attacker to control the USB device, trigger a disconnect while a userspace control descriptor remains open, and then generate callbacks that access freed memory. If successful, the attacker could gain kernel‑level execution on the affected system.
OpenCVE Enrichment
Debian DSA