{"id":"CVE-2026-80968","title":"kernel: ALSA: mts64: Check card index validity at probe (CVE-2026-80968)","summary":"A flaw was found in the ALSA mts64 driver within the Linux kernel. This driver does not properly validate the card index, specifically failing to check for negative ID values when bound via sysfs. A local attacker could exploit this vulner…","severity":"medium","cvss":5.5,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","cvssSource":"vendor","cwe":"CWE-787","vendor":"Red Hat","product":"Linux","affected":["Linux >= 68ab801e32bbe2caac8b8c6e6e94f41fe7d687ad < 1566ca99fc0e892b9164ad893d268b00064fff54","Linux >= 68ab801e32bbe2caac8b8c6e6e94f41fe7d687ad < 5d986d8c9e616636032636d99133f2535f94300d","Linux >= 68ab801e32bbe2caac8b8c6e6e94f41fe7d687ad < 5168a6241e953ecadb0ec05609649f6a7367fef8","Linux >= 68ab801e32bbe2caac8b8c6e6e94f41fe7d687ad < 9cd7c59a106e7267d0cbcf68670594584d8689d0","Linux >= 68ab801e32bbe2caac8b8c6e6e94f41fe7d687ad < 036e7aa793375ab16ea0f64b8de6673220416cc1","Linux >= 68ab801e32bbe2caac8b8c6e6e94f41fe7d687ad < a4e774eeb61aec64da5b03d3becffde26f7fe4de","Linux >= 68ab801e32bbe2caac8b8c6e6e94f41fe7d687ad < cf3af453a48c8d905512dfc44a5a59439b70f4f0","Linux >= 68ab801e32bbe2caac8b8c6e6e94f41fe7d687ad < d18a260720f86a5f8b5fcfefc4ba2e9dd01c10f8","Linux 2.6.19"],"published":"2026-09-11","updated":"2026-09-14","sourceUpdated":"2026-09-14T18:25:23+00:00","source":"CSAF","sourceUrl":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-80968.json","references":[{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-80968.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-80968"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2532220"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-80968"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-80968"},{"url":"https://git.kernel.org/pub/scm/linux/security/vulns.git/plain/cve/published/2026/CVE-2026-80968.mbox"},{"url":"https://git.kernel.org/stable/c/1566ca99fc0e892b9164ad893d268b00064fff54"},{"url":"https://git.kernel.org/stable/c/5d986d8c9e616636032636d99133f2535f94300d"},{"url":"https://git.kernel.org/stable/c/5168a6241e953ecadb0ec05609649f6a7367fef8"},{"url":"https://git.kernel.org/stable/c/9cd7c59a106e7267d0cbcf68670594584d8689d0"},{"url":"https://git.kernel.org/stable/c/036e7aa793375ab16ea0f64b8de6673220416cc1"},{"url":"https://git.kernel.org/stable/c/a4e774eeb61aec64da5b03d3becffde26f7fe4de"},{"url":"https://git.kernel.org/stable/c/cf3af453a48c8d905512dfc44a5a59439b70f4f0"},{"url":"https://git.kernel.org/stable/c/d18a260720f86a5f8b5fcfefc4ba2e9dd01c10f8"}],"tags":["csaf","vex","red-hat","cve.org"],"epss":0.0021,"epssPercentile":0.11546,"ingestedAt":"2026-09-14T15:23:07.455Z","slug":"CVE-2026-80968","body":"## Overview\n\nA flaw was found in the ALSA mts64 driver within the Linux kernel. This driver does not properly validate the card index, specifically failing to check for negative ID values when bound via sysfs. A local attacker could exploit this vulnerability to cause an out-of-bounds access, potentially leading to a denial of service or other memory corruption issues.\n\n## Vendor advisories\n\n- **Red Hat VEX** · Moderate · updated 2026-09-14 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-80968.json)\n\n**kernel: ALSA: mts64: Check card index validity at probe** — rated Moderate by Red Hat. Released 2026-09-11, updated 2026-09-14.\n\nNot affected:\n\n- Red Hat Enterprise Linux 10\n- Red Hat Enterprise Linux 6\n- Red Hat Enterprise Linux 7\n- Red Hat Enterprise Linux 8\n- Red Hat Enterprise Linux 9\n- Red Hat OpenShift Container Platform 4\n\n## Remediation\n\nRefer to the advisory for fix availability.","depth":"sunlit","depthScore":30,"depthScoreParts":{"impact":30.3,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[{"seq":204209,"id":"CVE-2026-80968","ts":1789490240179,"field":"cvss","old":null,"new":"5.5"},{"seq":204208,"id":"CVE-2026-80968","ts":1789490240179,"field":"severity","old":"none","new":"medium"},{"seq":147522,"id":"CVE-2026-80968","ts":1789270211236,"field":"cvss","old":null,"new":"4.7"},{"seq":147521,"id":"CVE-2026-80968","ts":1789270211236,"field":"severity","old":"none","new":"medium"},{"seq":109278,"id":"CVE-2026-80968","ts":1789183731251,"field":"cvss","old":null,"new":"4.7"},{"seq":109277,"id":"CVE-2026-80968","ts":1789183731251,"field":"severity","old":"none","new":"medium"}]}