CVE-2026-80966

Source
https://cve.org/CVERecord?id=CVE-2026-80966
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-80966.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2026-80966
Downstream
Related
Published
2026-09-11T19:42:31Z
Modified
2026-09-18T18:26:38Z
Summary
ALSA: portman2x4: Check card index validity at probe
Details

In the Linux kernel, the following vulnerability has been resolved:

ALSA: portman2x4: Check card index validity at probe

Although portman2x4 driver has a check of the given devptr->id value, it doesn't check for a negative id, which is often given as "none" or such value when bound via sysfs. This may lead to OOB access for index[] and other parameters.

Add a sanity check for the card index and warn/correct it if it's a value out of the range.

Database specific
{
    "cna_assigner":  "Linux",
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/80xxx/CVE-2026-80966.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
757e119bf52b014b3181eed97b01f87a245b8ff9
Fixed
45ea0707298798678a60ff861b695aea049a5469
Fixed
5d7ac5e9ee5ba76b567ace13b46075caf79dcca0
Fixed
0048994854f3e9c57b7a754de43ef8da5818d140
Fixed
64898e9bd8b7b229efa8642b85b56b326a6ec3dc
Fixed
0ce391090809d610647f424b9b1dc24aa2c546fd
Fixed
d7ef7890e3e35b4ba09e76fc6b72047a1599a5e8
Fixed
e1ce8ad1009b1736b3044b3324350dcfdd516f42
Fixed
3690ef20469d5959378260e2752f2314a2572913

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-80966.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
2.6.21
Fixed
5.10.270
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.221
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.188
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.157
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.109
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.50
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.4

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-80966.json"