Impact
The ALSA subsystem mishandles input synchronization for MIDI streams. During a rawmidi substream closure, the function snd_midi_input_event can still be executed, causing snd_rawmidi_input_trigger to be called while the underlying file descriptor has been cleared. This leads to a NULL pointer dereference and a kernel crash. The vulnerability is essentially a race condition that can bring the entire kernel down, resulting in a denial of service.
Affected Systems
This flaw exists in the ALSA sequencer module of the Linux kernel, which is shipped with all mainstream Linux distributions that support audio. The patch was added in commit ef7607ab1c8ad; kernel releases prior to that commit remain vulnerable. Administrators should confirm whether their distribution’s kernel includes the fix or has applied a backport. Systems running older kernel versions or unpatched modules that expose the ALSA device are at risk.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity, while the EPSS score of less than 1% suggests that exploitation probability is very low at present. The vulnerability is not in the CISA KEV catalog, implying no known active exploits. The attack vector would require access to the ALSA device and the ability to feed crafted MIDI input while the system is closing a stream, which typically means local or privileged access. Consequently, the risk is moderate to high for systems that run an affected kernel and use ALSA for MIDI input, especially on embedded systems or servers where the kernel might not be updated promptly.
OpenCVE Enrichment
Debian DLA
Debian DSA