Impact
A kernel configuration function that accepts a comma‑separated list of audio sampling rates parses the input without checking the number of tokens against the fixed‑size array limits. When more than the allowed ten entries are supplied, the function writes past the end of the array, corrupting kernel memory. This out‑of‑bounds write can overwrite control data or code pointers and may give an attacker an avenue to execute arbitrary code or crash the system.
Affected Systems
The flaw exists in the Linux kernel’s USB gadget UAC (USB Audio Class) implementation. Any distribution using a kernel that has not applied the fix is affected, as the vulnerability is not tied to a specific version in the available data.
Risk and Exploitability
The distributed CVSS score of 7.8 reflects a high severity, while the EPSS score of less than 1% indicates a low likelihood of immediate exploitation. The likely attack vector is writing to the configfs attributes exposed by the UAC gadget, which typically requires elevated privileges on the host. The vulnerability is not listed in the CISA Known Exploit Vulnerabilities catalog. The flaw is a classic out‑of-bounds buffer overflow (CWE-119) that can be leveraged for local privilege escalation or denial of service once the write is performed.
OpenCVE Enrichment