Impact
The foundation of this flaw lies in the ALSA Harmony driver within the Linux kernel. During device initialization, the driver registers its interrupt request (IRQ) before setting up its internal locks (h->lock and h->mixer_lock). If a hardware interrupt fires during this narrow window, the handling routine operates on uninitialized lock objects, leading to undefined behavior and possible kernel crashes. It is inferred from the description that this race condition can silently trigger a crash or corrupt kernel state. The vulnerability is a classic example of improper initialization, classified as CWE-665. The resulting impact is a denial of service, potentially causing system resets or availability loss for affected kernel builds. This impact description is inferred from the described crash behavior.
Affected Systems
The flaw affects all Linux kernel installations that ship the ALSA Harmony driver without the fix. The specific affected kernel versions are not enumerated in the advisory, but the vulnerability exists in any kernel that follows the unmodified code path described. Administrators running recent stable releases should verify whether they contain the patch that moves lock initialization before IRQ registration.
Risk and Exploitability
The CVSS score of 8.4 marks this as a high‑severity issue. With an EPSS score of less than 1 %, the likelihood of exploitation in the wild is currently low, and it is not cataloged in the CISA KEV list. Nonetheless, the attack requires low‑level kernel access or the ability to trigger a hardware interrupt, and the breach can occur during normal device operation. Because the vulnerability manifests as a race condition, it could be difficult to reproduce, yet a crash or state corruption would lead to a loss of functionality and potentially a reboot. Adopting a strict local privilege model and disabling unused drivers further reduces exposure.
OpenCVE Enrichment
Debian DLA
Debian DSA