Improper Validation of Array Index in Linux kernel - CVE-2026-80972
Published: September 12, 2026
Vulnerability details
The vulnerability allows a local user to perform an out-of-bounds memory access.
The vulnerability exists due to improper validation of a card index in the ALSA aloop driver's loopback_probe function when manually binding a device through the sysfs interface. A local user can provide an invalid card index to perform an out-of-bounds memory access.