Impact
The vulnerability is a NULL dereference triggered in the ALSA LED control layer of the Linux kernel when a write‑only kcontrol without a get callback is added. This flaw can cause an oops and crash the kernel, resulting in a denial‑of‑service condition. The impact is an abrupt kernel failure; there is no indication of privilege escalation or data loss.
Affected Systems
The defect is present in the Linux kernel for any configuration that allows the creation of custom ALSA kcontrols. No specific kernel versions are enumerated, so the issue applies to all kernels prior to the repository commit that introduced the fix. Systems that load ALSA modules and permit custom kcontrols are therefore impacted.
Risk and Exploitability
The EPSS score is below 1% and the flaw is not listed in CISA KEV, indicating a low probability of active exploitation. The vulnerability is local, requiring an actor with the ability to load or configure ALSA kcontrols, typically a local user. If exploited it would simply crash the kernel, enabling a local DoS attack through service interruption. The CVSS score is not provided, but the kernel crash implies significant impact.
OpenCVE Enrichment
Debian DLA
Debian DSA