Out-of-bounds read in Linux kernel - CVE-2026-80964
Published: September 12, 2026
Vulnerability details
The vulnerability allows a local user to perform an out-of-bounds read.
The vulnerability exists due to an out-of-bounds read in the ALSA virmidi driver probe function when manually binding a device through the sysfs interface with an invalid card index. A local user can manually bind a device with an invalid card index to perform an out-of-bounds read.