Impact
The loongson ALSA driver in the Linux kernel contains a flaw in the ACPI property parsing routine. In the function loongson_card_parse_acpi(), the return value of device_property_read_string() is ignored when reading the codec-dai-name property. When this property is missing or malformed, the driver subsequently dereferences an uninitialized pointer, which can lead to undefined behavior such as a kernel crash or memory corruption. This flaw is a use‑of‑uninitialized‑variable weakness that undermines kernel stability.
Affected Systems
All Linux kernels that include the loongson ALSA driver are affected. The vulnerability exists in any distro or custom kernel that compiles the loongson driver, as the issue is in the kernel source and not addressed by specific patch versions in the CVE description. The exact release versions are not specified, so any kernel containing the loongson driver without the applied fix is vulnerable.
Risk and Exploitability
The CVSS score of 8.4 indicates high severity, yet the EPSS score of less than 1 % suggests a very low probability of exploitation at this time. The issue is not listed in the CISA KEV catalog, implying no widespread incidents are known. Exploitation would require manipulation of ACPI properties during device initialization, which the likely attack vector is local or pre‑boot access on the target system. Because the flaw induces undefined behavior rather than an attacker‑controlled payload, the primary impact is a denial of service via kernel panic rather than privilege escalation. Therefore, while the theoretical impact is high, the realistic exploitation risk remains low until an attacker can modify ACPI firmware or utilize a local exploit during boot.
OpenCVE Enrichment
Debian DLA
Debian DSA