Impact
A use‑after‑free race exists in the ALSA sound subsystem when a managed sound card is unbound while a user space process still holds an open file descriptor. The kernel thread responsible for unbinding waits on a completion that is prematurely signaled by the user thread, freeing the card structure while the user thread is still executing cleanup logic. This leads to a KASAN report and potential dereference of freed memory, which can be exploited for arbitrary code execution or other kernel compromises.
Affected Systems
All Linux kernel builds that include the ALSA core driver are affected; no specific version range is listed, so any kernel containing the vulnerable code is at risk. The issue pertains to the sound subsystem and may impact any system that loads ALSA modules and runs user processes that open sound device files.
Risk and Exploitability
The EPSS score is less than 1%, indicating a very low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog, and no public exploitation has been reported. Because the race condition requires a local user to maintain an open file descriptor on a sound card while a device is being unbound, the attack vector is local and requires a privilege level sufficient to trigger the unbind operation. The potential impact is kernel memory corruption that can lead to privilege escalation or denial of service.
OpenCVE Enrichment
Debian DLA
Debian DSA