Impact
A race condition exists between non‑atomic ALSA PCM operations (hw_params, hw_free, prepare) and the atomic trigger‑start action. When two threads interleave a prepare request with a start trigger, the kernel may leave a PCM stream in an inconsistent state, causing warnings (e.g., ODEBUG) and potentially leading to driver crashes or malformed audio streams. This instability can be used to interrupt audio services, effectively denying proper audio functionality to applications.
Affected Systems
The flaw affects the ALSA PCM subsystem in the Linux kernel. All kernel releases prior to the inclusion of the race‑fix patch are susceptible, as the driver code does not guard against simultaneous non‑atomic operations and trigger requests. The issue is confined to the Linux:Linux vendor, impacting the core kernel audio components.
Risk and Exploitability
The CVSS score of 7.8 reflects a high severity, but the EPSS score of less than 1% indicates a very low probability of exploitation in the wild, and the flaw is not listed in the CISA KEV catalog. Exploitation requires a local attacker with sufficient privileges to spawn concurrent audio threads; the attack vector is therefore limited to local processes that use the ALSA API. Given the low EPSS and local nature, the overall risk is moderate but still significant enough to warrant prompt patching.
OpenCVE Enrichment
Debian DLA
Debian DSA