CVE-2026-80966EPSS p10.9%
CVE-2026-80966CVE-2026-80966
Description
In the Linux kernel, the following vulnerability has been resolved:
ALSA: portman2x4: Check card index validity at probe
Although portman2x4 driver has a check of the given devptr->id value,
it doesn't check for a negative id, which is often given as "none" or
such value when bound via sysfs. This may lead to OOB access for
index[] and other parameters.
Add a sanity check for the card index and warn/correct it if it's a
value out of the range.
Scoring
| EPSS | 0.22% probability of exploitation · percentile 10.9% · 2026-10-05T12:00:23Z |
| Last modified | 2026-09-14 |