Impact
The flaw causes a use‑after‑free and double free in the Linux ASoC meson driver during dynamic array reallocation. When the first krealloc() succeeds and the second fails, the driver frees a block that has already been freed, leaving card->dai_link pointing to an invalid block. The error path then dereferences that stale pointer, corrupting kernel memory. Based on the description, it is inferred that an attacker who can force this allocation sequence may crash the kernel or inject code, potentially escalating privileges.
Affected Systems
Any Linux kernel that includes the meson audio driver without the recent patch, regardless of distribution, is affected. No specific release lines are listed, so all unpatched kernel versions that contain the vulnerable code are vulnerable.
Risk and Exploitability
The CVSS score of 7.4 indicates a serious risk. The EPSS score of <1% shows that the likelihood of exploitation is very low at present, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that the flaw could be exploitable locally by an attacker able to trigger the reallocation failure path, but no public exploit is known.
OpenCVE Enrichment
Debian DLA
Debian DSA