Impact
The cs35l34 audio codec driver fails to drain its threaded interrupt request before entering runtime suspend. As a result, the interrupt handler can still execute after the device has been powered down and register access has been disabled. The handler reads volatile registers and may trigger firmware power‑down or release sequences, potentially corrupting the device state. This flaw is a race condition that could lead to unintended device behavior or system crashes.
Affected Systems
The vulnerability affects Linux kernel drivers implementing the Cirrus Logic CS35L34 codec. All kernel versions that include the cs35l34 driver without the patch are impacted; the flaw is specific to the ASoC subsystem in the Linux kernel.
Risk and Exploitability
The EPSS score is below 1 %, indicating a very low probability of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. The flaw requires local privileged access to the kernel to exploit effectively and occurs during the runtime power‑management cycle. The CVSS score is not provided, but the presence of a race condition that can cause device corruption or crash warrants attention from system administrators.
OpenCVE Enrichment
Debian DLA
Debian DSA