Out-of-bounds read in Linux kernel - CVE-2026-80812
Published: September 5, 2026
Vulnerability details
The vulnerability allows a local user to cause an out-of-bounds read.
The vulnerability exists due to improper validation in snd_dummy_probe() of the ALSA dummy driver when a platform device is manually bound through the sysfs interface with an invalid card index. A local user can bind a platform device with a card index of -1 to cause an out-of-bounds read.
Affected software
How to mitigate CVE-2026-80812
External References
- https://git.kernel.org/stable/c/02442d5fe8ee365a084b055d4fa81a0c1abfc3fd
- https://git.kernel.org/stable/c/3dba0e92e18980cb5a4d70a9a263539ae4f0c7ec
- https://git.kernel.org/stable/c/4d0892a90b57f0e89b274c3f3c51c2fa17937c88
- https://git.kernel.org/stable/c/690b721b9595f9a43395fd4047a832c42b5b6078
- https://git.kernel.org/stable/c/b20eb7ecbdaa3e649023fe41b177d90983ffb487
- https://git.kernel.org/stable/c/b7579e86afcec932e169d10e2d603abed8dd2fdf
- https://git.kernel.org/stable/c/c9f10a001c243d1f069ebb0e2f4999ad4043a254
- https://git.kernel.org/stable/c/f20c2c32ec1c5c3526f29a03b487c55a5890996c