{"id":"CVE-2026-80973","title":"kernel: ALSA: 6fire: bound the MIDI event length from the device (CVE-2026-80973)","summary":"A flaw was found in the Linux kernel's ALSA (Advanced Linux Sound Architecture) subsystem, specifically within the 6fire driver. This vulnerability allows a malicious USB device to trigger an out-of-bounds read by sending a specially craft…","severity":"high","cvss":7,"cvssVector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","cvssSource":"vendor","cwe":"CWE-125","vendor":"Red Hat","product":"Red Hat Enterprise Linux 9","affected":["enterprise_linux 10","enterprise_linux 6","enterprise_linux 7","enterprise_linux 8","enterprise_linux 9","openshift_container_platform 4"],"published":"2026-09-11","updated":"2026-09-14","sourceUpdated":"2026-09-14T14:48:49+00:00","source":"CSAF","sourceUrl":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-80973.json","references":[{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-80973.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-80973"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2532036"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-80973"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-80973"},{"url":"https://git.kernel.org/pub/scm/linux/security/vulns.git/plain/cve/published/2026/CVE-2026-80973.mbox"},{"url":"https://git.kernel.org/stable/c/c9204bc2ed2010e2469dbe5fce598878a37efd04"},{"url":"https://git.kernel.org/stable/c/2c590d5e1b1595d5c8fa0b72d2897423ce9985ca"},{"url":"https://git.kernel.org/stable/c/0c8a3c773823cf12abd39c480aed70e25c384630"},{"url":"https://git.kernel.org/stable/c/00e84a9ff2d43953ae261995cae94d46f4c307a6"},{"url":"https://git.kernel.org/stable/c/466e911bbbbb779bb06337e35a286e5ca7af16b3"},{"url":"https://git.kernel.org/stable/c/2a6f6fba3bd31d2e8c957fefa29156e35e5e75d5"},{"url":"https://git.kernel.org/stable/c/34816e2cfeabafb8eccf54687186ce25699e8363"},{"url":"https://git.kernel.org/stable/c/a478893b59e36cfe7d77a76b352f2db55502e879"}],"tags":["csaf","vex","red-hat","cve.org"],"epss":0.0021,"epssPercentile":0.11536,"ingestedAt":"2026-09-14T15:23:07.455Z","slug":"CVE-2026-80973","body":"## Overview\n\nA flaw was found in the Linux kernel's ALSA (Advanced Linux Sound Architecture) subsystem, specifically within the 6fire driver. This vulnerability allows a malicious USB device to trigger an out-of-bounds read by sending a specially crafted MIDI event with an excessive length. This can lead to the disclosure of sensitive information from kernel memory. The issue can be triggered upon device connection without requiring user interaction, provided a MIDI input substream is open.\n\n## Vendor advisories\n\n- **Red Hat VEX** · Moderate · affected: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9, Red Hat OpenShift Container Platform 4 · no fix planned: Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, … · updated 2026-09-14 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-80973.json)\n\n**kernel: ALSA: 6fire: bound the MIDI event length from the device** — rated Moderate by Red Hat. Released 2026-09-11, updated 2026-09-14.\n\nAffected:\n\n- Red Hat Enterprise Linux 10\n- Red Hat Enterprise Linux 6\n- Red Hat Enterprise Linux 7\n- Red Hat Enterprise Linux 8\n- Red Hat Enterprise Linux 9\n- Red Hat OpenShift Container Platform 4\n\nNo fix planned:\n\n- Red Hat Enterprise Linux 6\n- Red Hat Enterprise Linux 10\n- Red Hat Enterprise Linux 7\n- Red Hat Enterprise Linux 8\n- Red Hat Enterprise Linux 9\n- Red Hat OpenShift Container Platform 4\n\n## Remediation\n\nOut of support scope","depth":"twilight","depthScore":39,"depthScoreParts":{"impact":38.5,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[{"seq":202761,"id":"CVE-2026-80973","ts":1789403715766,"field":"cvss","old":null,"new":"7"},{"seq":202760,"id":"CVE-2026-80973","ts":1789403715766,"field":"severity","old":"none","new":"high"},{"seq":109630,"id":"CVE-2026-80973","ts":1789183732714,"field":"cvss","old":null,"new":"6.3"},{"seq":109629,"id":"CVE-2026-80973","ts":1789183732714,"field":"severity","old":"none","new":"medium"}]}