Improper Validation of Array Index in Linux kernel - CVE-2026-80969
Published: September 12, 2026
Vulnerability details
The vulnerability allows a local user to cause an out-of-bounds memory access.
The vulnerability exists due to improper validation of an array index in the ALSA mpu401 driver probe routine when manually binding a device through the sysfs interface with an invalid card index. A local user can set an invalid card index to cause an out-of-bounds memory access.