Impact
The Linux kernel’s ALSA System‑on‑Chip (ASoC) SOF IPC4 widget setup logic incorrectly reports success when the number of input or output formats is zero. Because the return value remains zero after a prior failure, callers assume the widget is set up correctly, leading to silent failures in audio configuration. This flaw represents improper error handling (CWE‑390) and does not directly enable privilege escalation or remote code execution, but it can degrade audio services or cause application instability.
Affected Systems
The vulnerability is present in all builds of the Linux kernel that include the affected ASoC SOF IPC4 widget code paths. Vendors that ship kernels without the patch may be impacted regardless of distribution or kernel version, as no specific release is identified in the data.
Risk and Exploitability
The EPSS score indicates a very low likelihood of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. Attackers would need local kernel access or the ability to influence widget configuration to trigger the flaw, making it primarily an integrity or availability concern rather than a direct external threat.
OpenCVE Enrichment