ALSA: mpu401: Check card index validity at probe
Summary
| CVE | CVE-2026-80969 |
|---|---|
| State | PUBLISHED |
| Assigner | Linux |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-09-11 20:19:02 UTC |
| Updated | 2026-09-13 07:17:03 UTC |
| Description | In the Linux kernel, the following vulnerability has been resolved: ALSA: mpu401: Check card index validity at probe mpu401 driver blindly trusts that the given devptr->id value is within the proper card index range at probe. It's OK for the devices the driver itself creates at the module probe time, but if the device is bound manually via sysfs interface, this could be -1 as "none", and this leads to OOB access for index[] and other parameters. Add a sanity check for the card index and warn/correct it if it's a value out of the range. |
Risk And Classification
EPSS: 0.002000000 probability, percentile 0.099330000 (date 2026-09-13)
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Linux | Linux | affected b3fe95123f0db79dd0345d249c312823178c11f5 76b6bc38d0f310c0ae1b2a2ebabe2947d92c601a git | Not specified |
| CNA | Linux | Linux | affected b3fe95123f0db79dd0345d249c312823178c11f5 cc4215cc2a4b2a9cf8b1952bbe8d5bf925acb3ea git | Not specified |
| CNA | Linux | Linux | affected b3fe95123f0db79dd0345d249c312823178c11f5 8adda66edf795d4648f8e26f312e4414c535d25a git | Not specified |
| CNA | Linux | Linux | affected b3fe95123f0db79dd0345d249c312823178c11f5 f7dcecb92ed192ff5fcf842918fb1aaea84b5bdd git | Not specified |
| CNA | Linux | Linux | affected 2.6.16 | Not specified |
| CNA | Linux | Linux | unaffected 2.6.16 semver | Not specified |
| CNA | Linux | Linux | unaffected 6.12.109 6.12.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.18.50 6.18.* semver | Not specified |
| CNA | Linux | Linux | unaffected 7.2.4 7.2.* semver | Not specified |
| CNA | Linux | Linux | unaffected 7.3-rc1 * original_commit_for_fix | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| git.kernel.org/stable/c/cc4215cc2a4b2a9cf8b1952bbe8d5bf925acb3ea | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/76b6bc38d0f310c0ae1b2a2ebabe2947d92c601a | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/8adda66edf795d4648f8e26f312e4414c535d25a | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/f7dcecb92ed192ff5fcf842918fb1aaea84b5bdd | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.