{"api_version":"1","generated_at":"2026-09-14T03:10:43+00:00","cve":"CVE-2026-80969","urls":{"html":"https://cve.report/CVE-2026-80969","api":"https://cve.report/api/cve/CVE-2026-80969.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-80969","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-80969"},"summary":{"title":"ALSA: mpu401: Check card index validity at probe","description":"In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: mpu401: Check card index validity at probe\n\nmpu401 driver blindly trusts that the given devptr->id value is within\nthe proper card index range at probe.  It's OK for the devices the\ndriver itself creates at the module probe time, but if the device is\nbound manually via sysfs interface, this could be -1 as \"none\", and\nthis leads to OOB access for index[] and other parameters.\n\nAdd a sanity check for the card index and warn/correct it if it's a\nvalue out of the range.","state":"PUBLISHED","assigner":"Linux","published_at":"2026-09-11 20:19:02","updated_at":"2026-09-13 07:17:03"},"problem_types":[],"metrics":[],"references":[{"url":"https://git.kernel.org/stable/c/cc4215cc2a4b2a9cf8b1952bbe8d5bf925acb3ea","name":"https://git.kernel.org/stable/c/cc4215cc2a4b2a9cf8b1952bbe8d5bf925acb3ea","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/76b6bc38d0f310c0ae1b2a2ebabe2947d92c601a","name":"https://git.kernel.org/stable/c/76b6bc38d0f310c0ae1b2a2ebabe2947d92c601a","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/8adda66edf795d4648f8e26f312e4414c535d25a","name":"https://git.kernel.org/stable/c/8adda66edf795d4648f8e26f312e4414c535d25a","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/f7dcecb92ed192ff5fcf842918fb1aaea84b5bdd","name":"https://git.kernel.org/stable/c/f7dcecb92ed192ff5fcf842918fb1aaea84b5bdd","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-80969","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-80969","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected b3fe95123f0db79dd0345d249c312823178c11f5 76b6bc38d0f310c0ae1b2a2ebabe2947d92c601a git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected b3fe95123f0db79dd0345d249c312823178c11f5 cc4215cc2a4b2a9cf8b1952bbe8d5bf925acb3ea git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected b3fe95123f0db79dd0345d249c312823178c11f5 8adda66edf795d4648f8e26f312e4414c535d25a git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected b3fe95123f0db79dd0345d249c312823178c11f5 f7dcecb92ed192ff5fcf842918fb1aaea84b5bdd git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 2.6.16","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 2.6.16 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.12.109 6.12.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.18.50 6.18.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.2.4 7.2.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.3-rc1 * original_commit_for_fix","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2026","cve_id":"80969","cve":"CVE-2026-80969","epss":"0.002000000","percentile":"0.099330000","score_date":"2026-09-13","updated_at":"2026-09-14 00:18:01"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"Linux","programFiles":["sound/drivers/mpu401/mpu401.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"lessThan":"76b6bc38d0f310c0ae1b2a2ebabe2947d92c601a","status":"affected","version":"b3fe95123f0db79dd0345d249c312823178c11f5","versionType":"git"},{"lessThan":"cc4215cc2a4b2a9cf8b1952bbe8d5bf925acb3ea","status":"affected","version":"b3fe95123f0db79dd0345d249c312823178c11f5","versionType":"git"},{"lessThan":"8adda66edf795d4648f8e26f312e4414c535d25a","status":"affected","version":"b3fe95123f0db79dd0345d249c312823178c11f5","versionType":"git"},{"lessThan":"f7dcecb92ed192ff5fcf842918fb1aaea84b5bdd","status":"affected","version":"b3fe95123f0db79dd0345d249c312823178c11f5","versionType":"git"}]},{"defaultStatus":"affected","product":"Linux","programFiles":["sound/drivers/mpu401/mpu401.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"status":"affected","version":"2.6.16"},{"lessThan":"2.6.16","status":"unaffected","version":"0","versionType":"semver"},{"lessThanOrEqual":"6.12.*","status":"unaffected","version":"6.12.109","versionType":"semver"},{"lessThanOrEqual":"6.18.*","status":"unaffected","version":"6.18.50","versionType":"semver"},{"lessThanOrEqual":"7.2.*","status":"unaffected","version":"7.2.4","versionType":"semver"},{"lessThanOrEqual":"*","status":"unaffected","version":"7.3-rc1","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"cpeMatch":[{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.12.109","versionStartIncluding":"2.6.16","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.18.50","versionStartIncluding":"2.6.16","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.2.4","versionStartIncluding":"2.6.16","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.3-rc1","versionStartIncluding":"2.6.16","vulnerable":true}],"negate":false,"operator":"OR"}]}],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: mpu401: Check card index validity at probe\n\nmpu401 driver blindly trusts that the given devptr->id value is within\nthe proper card index range at probe.  It's OK for the devices the\ndriver itself creates at the module probe time, but if the device is\nbound manually via sysfs interface, this could be -1 as \"none\", and\nthis leads to OOB access for index[] and other parameters.\n\nAdd a sanity check for the card index and warn/correct it if it's a\nvalue out of the range."}],"providerMetadata":{"dateUpdated":"2026-09-13T06:23:59.473Z","orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux"},"references":[{"url":"https://git.kernel.org/stable/c/76b6bc38d0f310c0ae1b2a2ebabe2947d92c601a"},{"url":"https://git.kernel.org/stable/c/cc4215cc2a4b2a9cf8b1952bbe8d5bf925acb3ea"},{"url":"https://git.kernel.org/stable/c/8adda66edf795d4648f8e26f312e4414c535d25a"},{"url":"https://git.kernel.org/stable/c/f7dcecb92ed192ff5fcf842918fb1aaea84b5bdd"}],"title":"ALSA: mpu401: Check card index validity at probe","x_generator":{"engine":"bippy-1.2.0"}}},"cveMetadata":{"assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","assignerShortName":"Linux","cveId":"CVE-2026-80969","datePublished":"2026-09-11T19:42:33.128Z","dateReserved":"2026-08-26T14:34:25.810Z","dateUpdated":"2026-09-13T06:23:59.473Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-09-11 20:19:02","lastModifiedDate":"2026-09-13 07:17:03","problem_types":[],"metrics":[],"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"80969","Ordinal":"1","Title":"ALSA: mpu401: Check card index validity at probe","CVE":"CVE-2026-80969","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"80969","Ordinal":"1","NoteData":"In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: mpu401: Check card index validity at probe\n\nmpu401 driver blindly trusts that the given devptr->id value is within\nthe proper card index range at probe.  It's OK for the devices the\ndriver itself creates at the module probe time, but if the device is\nbound manually via sysfs interface, this could be -1 as \"none\", and\nthis leads to OOB access for index[] and other parameters.\n\nAdd a sanity check for the card index and warn/correct it if it's a\nvalue out of the range.","Type":"Description","Title":"ALSA: mpu401: Check card index validity at probe"}]}}}