Impact
The cs35l33 ASoC driver in the Linux kernel allows a race condition between runtime suspend operations and an interrupt handler. During runtime PM the driver powers the codec down and enables regcache_cache_only, but it does not drain the threaded IRQ that is still registered. If the handler runs in the narrow window after cache_only is activated, it continues to read volatile status registers and attempts to drive release paths on the codec after power has been removed. This unchecked access can cause the driver to execute invalid hardware commands, potentially corrupting internal state or triggering a crash. The weakness can lead to loss of audio functionality or, in worst case, system instability and denial of service.
Affected Systems
The flaw exists in the Linux kernel in the ALSA System on Chip (ASoC) stack, specifically the cs35l33 codec driver. Any Linux system that uses the cs35l33 audio codec and enables runtime PM for the driver is affected. The issue is present in kernel versions before the fix; the precise version range is not enumerated in the data, so all affected kernels containing the unpatched driver should be examined. The vendor is Linux (kernel team).
Risk and Exploitability
This is a local code execution or denial of service risk that requires privileged access to the running system because it involves manipulating kernel driver behavior. The EPSS score is noted as <1%, indicating a very low but non‑zero probability of exploitation at the time of analysis. The vulnerability is not included in the CISA KEV catalog, reflecting limited known exploitation activity. The flaw is a classic race condition (CWE‑362) and could be triggered by an attacker capable of forcing the system into runtime suspend while the codec driver remains active and still has unmasked interrupts. However, because it relies on timing and the driver state, it is moderately difficult to exploit reliably.
OpenCVE Enrichment
Debian DLA
Debian DSA