Impact
The flaw is an off‑by‑one error in the ALSA System on a Chip (ASoC) sound subsystem. When a second enum channel value is processed, the code accepts an index that equals the number of items and then proceeds to read the values array without checking that the second index is within bounds. This can cause an out‑of‑bounds read of kernel memory containing audio control data. If an attacker can influence the value written to the control, they can read arbitrary kernel memory, potentially leaking sensitive information. The vulnerability is read‑only and does not allow code execution, but a memory disclosure could aid in privilege escalation.
Affected Systems
The defect exists in every Linux kernel release that has not incorporated the recent patch correcting the enum channel boundary check. All distributions and vendors that ship a kernel with the affected ASoC code paths are impacted, regardless of the specific version number.
Risk and Exploitability
The EPSS score is reported as less than 1 %, indicating a very low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires a local privilege or the ability to manipulate audio controls; the flaw is limited to reads, so the attack vector is likely local or available to users who have write access to sound controls. While the lack of public exploitation evidence reduces the immediate threat, the read‑out‑of‑bounds behavior still poses a moderate to potentially high risk in environments where audio controls are exposed to untrusted processes or networks. Prompt patching is therefore strongly recommended.
OpenCVE Enrichment
Debian DLA
Debian DSA