{"id":"CVE-2026-80972","title":"kernel: ALSA: aloop: Check card index validity at probe (CVE-2026-80972)","summary":"A flaw was found in the ALSA (Advanced Linux Sound Architecture) aloop driver within the Linux kernel. This vulnerability arises from insufficient validation of the card index during device setup, specifically when a device is manually con…","severity":"medium","cvss":5.5,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","cvssSource":"vendor","cwe":"CWE-125","vendor":"Red Hat","product":"Red Hat Enterprise Linux 9","affected":["enterprise_linux 10","enterprise_linux 6","enterprise_linux 7","enterprise_linux 8","enterprise_linux 9","openshift_container_platform 4"],"published":"2026-09-11","updated":"2026-09-14","sourceUpdated":"2026-09-14T18:26:23+00:00","source":"CSAF","sourceUrl":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-80972.json","references":[{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-80972.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-80972"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2532492"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-80972"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-80972"},{"url":"https://git.kernel.org/pub/scm/linux/security/vulns.git/plain/cve/published/2026/CVE-2026-80972.mbox"},{"url":"https://git.kernel.org/stable/c/6da6ffb34a5d54e7e6efebb253899c6a3501a611"},{"url":"https://git.kernel.org/stable/c/e35d11102ef0945feaa1dba4e511685911695ab9"},{"url":"https://git.kernel.org/stable/c/6fe7d13608a9d1cf5aff9decc0cc653b0f38f537"},{"url":"https://git.kernel.org/stable/c/c589aeaadfde1cfedb5c6f0a3c782807282126d9"},{"url":"https://git.kernel.org/stable/c/7b3f9855849363e402bf2141df2b428581cbf31b"},{"url":"https://git.kernel.org/stable/c/efbc2e9e43a1b5c6d75ae47439c06896bb142ae6"},{"url":"https://git.kernel.org/stable/c/819b106a9fd2ef3fd8abf898b9a8e4524eca8f48"}],"tags":["csaf","vex","red-hat","cve.org"],"epss":0.00172,"epssPercentile":0.06961,"ingestedAt":"2026-09-14T15:23:07.455Z","slug":"CVE-2026-80972","body":"## Overview\n\nA flaw was found in the ALSA (Advanced Linux Sound Architecture) aloop driver within the Linux kernel. This vulnerability arises from insufficient validation of the card index during device setup, specifically when a device is manually configured using the sysfs interface. A local attacker could exploit this by providing an invalid card index, leading to an out-of-bounds memory access. This could result in memory corruption, potentially affecting system stability or data integrity.\n\n## Vendor advisories\n\n- **Red Hat VEX** · Moderate · affected: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9, Red Hat OpenShift Container Platform 4 · no fix planned: Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, … · updated 2026-09-14 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-80972.json)\n\n**kernel: ALSA: aloop: Check card index validity at probe** — rated Moderate by Red Hat. Released 2026-09-11, updated 2026-09-14.\n\nAffected:\n\n- Red Hat Enterprise Linux 10\n- Red Hat Enterprise Linux 6\n- Red Hat Enterprise Linux 7\n- Red Hat Enterprise Linux 8\n- Red Hat Enterprise Linux 9\n- Red Hat OpenShift Container Platform 4\n\nNo fix planned:\n\n- Red Hat Enterprise Linux 6\n- Red Hat Enterprise Linux 10\n- Red Hat Enterprise Linux 7\n- Red Hat Enterprise Linux 8\n- Red Hat Enterprise Linux 9\n- Red Hat OpenShift Container Platform 4\n\n## Remediation\n\nOut of support scope","depth":"sunlit","depthScore":30,"depthScoreParts":{"impact":30.3,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[{"seq":204197,"id":"CVE-2026-80972","ts":1789490240117,"field":"cvss","old":null,"new":"5.5"},{"seq":204196,"id":"CVE-2026-80972","ts":1789490240117,"field":"severity","old":"none","new":"medium"},{"seq":147115,"id":"CVE-2026-80972","ts":1789270195232,"field":"cvss","old":null,"new":"5.2"},{"seq":147114,"id":"CVE-2026-80972","ts":1789270195232,"field":"severity","old":"none","new":"medium"},{"seq":108874,"id":"CVE-2026-80972","ts":1789183729354,"field":"cvss","old":null,"new":"5.2"},{"seq":108873,"id":"CVE-2026-80972","ts":1789183729354,"field":"severity","old":"none","new":"medium"}]}