Impact
The Linux kernel :hdac_hda: audio driver acquires a reference to an HDA link before registering an ASoC component. If registration fails, the driver returns without releasing that reference, creating a reference‑count leak. Over time a repeated failure could accumulate unreleased references and exhaust kernel resources, potentially causing a denial of service. This flaw is a classic resource‑leak weakness (CWE‑911).
Affected Systems
All Linux kernel builds that incorporate the hdac_hda driver before the patch are potentially affected. No specific kernel version numbers are listed; therefore any system still running the unpatched audio driver could be vulnerable. The issue is confined to the HDA audio subsystem of the kernel.
Risk and Exploitability
Based on the description, it is inferred that an attacker could trigger the leak by repeatedly causing ASoC component registration failures, which would lead to resource exhaustion and a denial of service. The likely attack vector is a local user with the ability to force component registration failures. The EPSS score of less than 1% indicates a very low current exploitation probability, and the vulnerability is not listed in the CISA KEV catalog. The CVSS score of 5.5 denotes moderate severity. Given the low likelihood of exploitation but potentially high impact if triggered, the overall risk can be considered moderate.
OpenCVE Enrichment
Debian DLA
Debian DSA