Impact
The bug in the Linux ASoC rt700-sdw driver allows queued work functions (jack_detect_work and jack_btn_check_work) to remain pending during a device removal sequence when the hardware initialization flag is cleared too early. If the device enters the UNATTACHED state while work is queued, the removal path may skip draining these work objects, causing them to execute after the codec data has been freed. The inferred use‑after‑free condition suggests the possibility of a kernel crash, leading to system instability or denial of service.
Affected Systems
The flaw affects the Linux kernel, specifically the rt700-sdw component of the Advanced Linux Sound Architecture subsystem. Any kernel version that includes the unpatched rt700 driver is susceptible. The CNA identifies the product as Linux, Linux, with no specific version range provided.
Risk and Exploitability
The EPSS score is reported to be less than 1 % and the vulnerability is not listed in the CISA KEV catalog, indicating a low probability of known exploitation. However, the flaw is a local kernel bug that can cause a crash if an attacker can trigger a device removal while the use‑after‑free condition is pending. The inference that this can lead to a kernel crash is derived from the description. It would require privileged or local access to the affected hardware to manipulate the removal sequence; thus the attack vector is local. The intrinsic severity is high due to the potential for a full kernel panic, but realistic exploitation likelihood remains low given the required preparation.
OpenCVE Enrichment
Debian DLA
Debian DSA