Out-of-bounds read in Linux kernel - CVE-2026-80973

 

Out-of-bounds read in Linux kernel - CVE-2026-80973

Published: September 12, 2026


Vulnerability identifier: #VU149421
CSH Severity: Medium
CVSS v4: 5.1 [CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-80973
CWE-ID: CWE-125
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows an attacker with physical access to disclose kernel memory.

The vulnerability exists due to an out-of-bounds read in usb6fire_comm_receiver_handler() when processing MIDI events from a connected USB device. An attacker with physical access can provide a MIDI event with an excessive length value to disclose kernel memory.

The receiver is submitted during device probing, and forwarding data through the rawmidi read path requires an open MIDI input substream.


Affected software

Linux kernel

How to mitigate CVE-2026-80973

Install security update from vendor's repository.


External References

Related Security Bulletins