Impact
The ALSA ice1712 driver in the Linux kernel does not release the ALSA card object if later initialization steps fail during the probe. This results in a kernel memory leak that can grow unchecked if probe failures occur repeatedly, potentially exhausting kernel memory and causing system instability or denial of service.
Affected Systems
All builds of the Linux kernel that include the original ALSA ice1712 driver before the applied fix are impacted. The vendor is Linux, and the specific affected versions are not enumerated in the data.
Risk and Exploitability
The CVSS score is 5.5, indicating moderate severity. The EPSS score is below 1%, indicating a low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog, and no public exploit has been disclosed. The description indicates the flaw arises during driver initialization; based on this, it is inferred that an attacker would need privileges sufficient to load or unload kernel modules or reboot the system. The risk is moderate because lack of exploitation vectors mitigates immediate danger, yet repeated probe failures could lead to resource exhaustion.
OpenCVE Enrichment
Debian DLA
Debian DSA