Improper Validation of Array Index in Linux kernel - CVE-2026-80965
Published: September 12, 2026
Vulnerability details
The vulnerability allows a local user to cause an out-of-bounds access.
The vulnerability exists due to improper validation of a card index in the ALSA serial-u16550 driver's snd_serial_probe function when manually binding a device through the sysfs interface. A local user can bind a device with an invalid card index to cause an out-of-bounds access.