Impact
Register writes performed by the fsl_audmix driver while the device is still powered off cause the hardware to hang. This occurs between probe and the first runtime resume, when the PM framework has not yet enabled the clocks. The flaw is an initialization error that allows kernel code to write to a device that is not yet ready, resulting in a system halt. It aligns with the weakness of calling functions before a component’s state is valid, a common form of improper initialization.
Affected Systems
All Linux kernel builds that include the fsl_audmix component, regardless of vendor, are potentially affected when runtime PM is enabled. The issue is present in kernel versions that have not incorporated the commit series that restores correct PM handling, specifically those compiled with CONFIG_PM and without explicit hardware initialization during probe. The exact version range is not provided, so any kernel before the fix should be considered vulnerable, especially on hardware platforms that use the ALSA/fsl_audmix driver.
Risk and Exploitability
The EPSS score is below 1 % and the vulnerability is not listed in the CISA KEV catalog, indicating a low exploitation probability. However, the vulnerability requires privileged kernel execution and access to the affected audio hardware, therefore it is a local denial‑of‑service risk. Exploitation would be straightforward once the driver loads; an attacker could trigger the hang by invoking any ALSA control that writes to the device after driver initialization. The severity of the impact is high for systems that rely on continuous audio processing, but the likelihood of targeted attacks remains low.
OpenCVE Enrichment
Debian DLA
Debian DSA