Impact
The flaw occurs when a USBTV audio device is disconnected while an ALSA PCM stream remains open. State information stored in the PCM private data is freed by the USB disconnect path before the ALSA substream is closed, resulting in a use‑after‑free when snd_usbtv_pcm_close() dereferences the freed structure. This kernel memory corruption can lead to a crash or, if an attacker controls the freed memory contents, arbitrary code execution. The weakness is a classic use‑after‑free vulnerability.
Affected Systems
All Linux kernel versions that include the usbtv media driver and provide ALSA audio support are affected. The bug manifests on any system that plugs in a USBTV device while an ALSA PCM stream is open, without a known restricted version list. Linux kernel distributions that ship the usbtv driver prior to the patch contain the flaw.
Risk and Exploitability
The CVSS score of 7.8 indicates a high‑severity vulnerability, and the EPSS score of less than 1% indicates a low likelihood of exploitation in the wild. The flaw is not currently listed in the CISA KEV catalog. Exploitation would likely require local or device‑level privileged USB access to insert a malicious USBTV cable while a PCM stream is active, after which the system could crash or the attacker could achieve kernel code execution. Given the low EPSS, the risk is moderate but should be mitigated promptly.
OpenCVE Enrichment
Debian DLA
Debian DSA