---
id: CVE-2026-80966
title: 'kernel: ALSA: portman2x4: Check card index validity at probe (CVE-2026-80966)'
summary: >-
  A flaw was found in the ALSA portman2x4 driver of the Linux kernel. This
  vulnerability occurs because the driver does not properly validate the card
  index, specifically failing to check for negative ID values. A local attacker
  could exploi…
severity: medium
cvss: 5.5
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'
cvssSource: vendor
cwe: CWE-125
vendor: Red Hat
product: Linux
affected:
  - >-
    Linux >= 757e119bf52b014b3181eed97b01f87a245b8ff9 <
    45ea0707298798678a60ff861b695aea049a5469
  - >-
    Linux >= 757e119bf52b014b3181eed97b01f87a245b8ff9 <
    5d7ac5e9ee5ba76b567ace13b46075caf79dcca0
  - >-
    Linux >= 757e119bf52b014b3181eed97b01f87a245b8ff9 <
    0048994854f3e9c57b7a754de43ef8da5818d140
  - >-
    Linux >= 757e119bf52b014b3181eed97b01f87a245b8ff9 <
    64898e9bd8b7b229efa8642b85b56b326a6ec3dc
  - >-
    Linux >= 757e119bf52b014b3181eed97b01f87a245b8ff9 <
    0ce391090809d610647f424b9b1dc24aa2c546fd
  - >-
    Linux >= 757e119bf52b014b3181eed97b01f87a245b8ff9 <
    d7ef7890e3e35b4ba09e76fc6b72047a1599a5e8
  - >-
    Linux >= 757e119bf52b014b3181eed97b01f87a245b8ff9 <
    e1ce8ad1009b1736b3044b3324350dcfdd516f42
  - >-
    Linux >= 757e119bf52b014b3181eed97b01f87a245b8ff9 <
    3690ef20469d5959378260e2752f2314a2572913
  - Linux 2.6.21
published: '2026-09-11'
updated: '2026-09-14'
sourceUpdated: '2026-09-14T18:25:18+00:00'
source: CSAF
sourceUrl: 'https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-80966.json'
references:
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-80966.json
  - url: 'https://access.redhat.com/security/cve/CVE-2026-80966'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2532285'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-80966'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-80966'
  - url: >-
      https://git.kernel.org/pub/scm/linux/security/vulns.git/plain/cve/published/2026/CVE-2026-80966.mbox
  - url: 'https://git.kernel.org/stable/c/45ea0707298798678a60ff861b695aea049a5469'
  - url: 'https://git.kernel.org/stable/c/5d7ac5e9ee5ba76b567ace13b46075caf79dcca0'
  - url: 'https://git.kernel.org/stable/c/0048994854f3e9c57b7a754de43ef8da5818d140'
  - url: 'https://git.kernel.org/stable/c/64898e9bd8b7b229efa8642b85b56b326a6ec3dc'
  - url: 'https://git.kernel.org/stable/c/0ce391090809d610647f424b9b1dc24aa2c546fd'
  - url: 'https://git.kernel.org/stable/c/d7ef7890e3e35b4ba09e76fc6b72047a1599a5e8'
  - url: 'https://git.kernel.org/stable/c/e1ce8ad1009b1736b3044b3324350dcfdd516f42'
  - url: 'https://git.kernel.org/stable/c/3690ef20469d5959378260e2752f2314a2572913'
tags:
  - csaf
  - vex
  - red-hat
  - cve.org
epss: 0.0021
epssPercentile: 0.11565
ingestedAt: '2026-09-14T15:23:07.455Z'
---

## Overview

A flaw was found in the ALSA portman2x4 driver of the Linux kernel. This vulnerability occurs because the driver does not properly validate the card index, specifically failing to check for negative ID values. A local attacker could exploit this by providing a negative ID value via sysfs, leading to an out-of-bounds memory access. This could potentially result in system instability or information disclosure.

## Vendor advisories

- **Red Hat VEX** · Moderate · updated 2026-09-14 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-80966.json)

**kernel: ALSA: portman2x4: Check card index validity at probe** — rated Moderate by Red Hat. Released 2026-09-11, updated 2026-09-14.

Not affected:

- Red Hat Enterprise Linux 10
- Red Hat Enterprise Linux 6
- Red Hat Enterprise Linux 7
- Red Hat Enterprise Linux 8
- Red Hat Enterprise Linux 9
- Red Hat OpenShift Container Platform 4

## Remediation

Refer to the advisory for fix availability.
