Improper Validation of Array Index in Linux kernel - CVE-2026-80968
Published: September 12, 2026
Vulnerability details
The vulnerability allows a local user to cause an out-of-bounds access.
The vulnerability exists due to improper validation of an array index in the ALSA mts64 driver's snd_mts64_probe function when binding a device through sysfs with a negative card index. A local user can provide a negative card index to cause an out-of-bounds access.