Impact
During media driver initialization the kernel allocates an object for the Cobalt audio device and registers a free callback. If initialization fails after the object is allocated, the code frees it twice: once through the ALSA card cleanup path and again manually. This double‑free can corrupt kernel memory and, while an exploitation path is not detailed in the description, such a flaw could allow privilege escalation or system instability if an attacker can trigger the failure scenario. The flaw is identified as CWE‑416, a classic use‑after‑free weakness. Based on the description, it is inferred that an attacker could trigger the failure by supplying malformed audio data during device initialization, implying a local privilege escalation vector via the driver.
Affected Systems
The vulnerability affects the Linux kernel’s media subsystem, specifically the cobalt driver. All kernel versions prior to the fix are potentially impacted; the exact version range is not specified, but any kernel containing the flawed code path is vulnerable.
Risk and Exploitability
The EPSS score is reported as less than 1 percent, indicating a low probability of exploitation, and the vulnerability is not listed in CISA's KEV catalog. However double‑free bugs in the kernel are often considered severe because they can lead to privilege escalation. Based on the description, it is inferred that exploitation would require an attacker to induce initialization failure, possibly through crafted input to the cobalt driver, which suggests a local target attack scenario. In the absence of a publicly documented exploit, the risk is moderate but should be treated with caution, especially in environments where kernel stability is critical.
OpenCVE Enrichment
Debian DLA
Debian DSA