Impact
An ASoc Xilinx formatter PCM driver in the Linux kernel allocates stream data early during open and assigns it to a substream pointer. If a subsequent hardware constraint call fails, the driver returns immediately without freeing the allocated structure. The ALSA subsystem does not invoke a close callback for a failed open, leaving the stream pointer dangling. When an interrupt later triggers the period elapsed handler, it accesses the freed substream, causing a use-after-free condition that can crash the kernel or provide a foothold for code execution. This flaw maps to CWE-416, the use-after-free weakness.
Affected Systems
The vulnerability resides in the Linux kernel’s ASoc Xilinx formatter PCM driver. All kernel releases lacking the patch that clears stream_data on error are affected. No specific vendor or product sub-versions are listed, so the issue applies broadly to any Linux kernel that includes the older Xilinx driver code.
Risk and Exploitability
The EPSS score is below 1% and the flaw is not listed in CISA KEV, indicating a low likelihood of widespread exploitation. The weakness requires a local user with ability to open the PCM device, so the attack vector is local. Although the unpatched code can result in a kernel crash or potential privilege escalation, the absence of a public exploit and the restrictive user context suggest remediation priority is medium; nevertheless a patch should be applied as soon as possible.
OpenCVE Enrichment
Debian DLA
Debian DSA