Impact
In the Linux kernel’s ASoC: SOF audio subsystem, the topology mixer records minimum and maximum volume indices in signed fields. The code allocates a table of size "max + 1" based on these values and later indexes the table with the stored range. If an inverted range or a maximum value close to INT_MAX is supplied, the allocation can overflow and the indices may fall outside the allocated memory, leading to memory corruption that can crash the kernel. This loss of stability manifests as a denial of service.
Affected Systems
All Linux kernel builds that contain the ASoC: SOF audio subsystem and lack the fix introduced by commit 72d0b77412aef2cec554cc84e176658f2a48dafa are potentially affected. Since the patch applies to all kernel versions prior to that commit, any system running an unpatched kernel that includes the SOF audio module is vulnerable.
Risk and Exploitability
EPSS indicates a probability of exploitation that is less than 1 %, and the vulnerability is not listed in the CISA KEV catalog, suggesting a low current exploitation risk. The kernel context and lack of a public CVSS score imply that local exploitation may require an attacker to influence the topology configuration, such as by loading a malicious or improperly configured driver. This is inferred from the description because the exact attack vector is not explicitly detailed in the CVE entry. The likely attack vector is local privileged code that configures invalid audio parameters, but this is not confirmed in the advisory.
OpenCVE Enrichment
Debian DLA
Debian DSA