Impact
The ALSA mtpav driver in the Linux kernel schedules an output timer that can be re‑armed by a callback executing on a different CPU. During card teardown the driver releases the spinlock and deletes the timer, but it does not wait for any callbacks that are currently running. As a result, the callback may continue after the driver has been freed, accessing freed memory and potentially re‑arming the timer. This race condition can lead to a use‑after‑free vulnerability that may allow an attacker to execute arbitrary code in kernel space.
Affected Systems
Linux kernel, specifically the ALSA mtpav audio driver. No specific version information is listed in the advisory.
Risk and Exploitability
The CVSS score is not disclosed in the provided data, but the EPSS identifier of less than 1% indicates a very low probability that this race condition would be exploited in practice. The vulnerability is not listed in the CISA KEV catalog, further suggesting it is not currently being actively exploited. An attacker would need local access and a precise timing window where a callback is still running while the audio card is being torn down, a scenario that is relatively narrow and unlikely.
OpenCVE Enrichment