Integer underflow in Linux kernel - CVE-2026-80900
Published: September 5, 2026
Vulnerability details
The vulnerability allows a local user to access memory outside the UMP buffer bounds.
The vulnerability exists due to an integer underflow in ASoC SDCA UMP message size checks when handling UMP messages whose offset is larger than the buffer length. A local user can provide a crafted UMP message with an oversized offset to access memory outside the UMP buffer bounds.