Impact
This vulnerability resides in the ALSA sequencer of the Linux kernel. During error handling, the bounce_error_event() routine embeds the failed event directly into the bounce payload by pointing data.ext.ptr at it. When that event is a queued variable‑length event, its own data.ext.ptr holds the address of its first extension cell. The payload is then transmitted unmodified, exposing that internal address to userspace. The effect is that an attacker can obtain a kernel‑space pointer value, which may be used for subsequent information‑disclosure attacks or lead to privilege escalation. The weakness is a classic information‑leak flaw (CWE‑200).
Affected Systems
The flaw affects all Linux kernel implementations that contain the ALSA sequencer before the fix that removed the pointer from the event header. Packages that ship the kernel before the commit referenced in the advisory are vulnerable. The advisory lists Linux as the affected vendor; specific product versions are not enumerated in the data.
Risk and Exploitability
The EPSS score is below 1%, and it is not listed in CISA’s KEV catalog, suggesting low exploitation probability. However, the attack can be carried out by any unprivileged local user who can set the SNDRV_SEQ_FILTER_BOUNCE flag, queue a variable‑length event to a nonexistent ALSA port, and read the bounce response. Although the vulnerability is local, an attacker may leverage the disclosed address to carry out additional kernel‑based exploits. The CVSS score is not provided; nevertheless the combination of local access and kernel memory disclosure warrants attention.
OpenCVE Enrichment
Debian DLA
Debian DSA