CVE-2026-80972Medium· 5.5▾ SunlitA flaw was found in the ALSA (Advanced Linux Sound Architecture) aloop driver within the Linux kernel. This vulnerability arises from insufficient validation of the card index during device setup, specifically when a device is manually con…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 30.3 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 12.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via CSAF
0.2%
— → 5.2
none → medium
— → 5.2
none → medium
Last analysed / modified upstream
0.2% → 0.2%
— → 5.5
none → medium
A flaw was found in the ALSA (Advanced Linux Sound Architecture) aloop driver within the Linux kernel. This vulnerability arises from insufficient validation of the card index during device setup, specifically when a device is manually configured using the sysfs interface. A local attacker could exploit this by providing an invalid card index, leading to an out-of-bounds memory access. This could result in memory corruption, potentially affecting system stability or data integrity.
kernel: ALSA: aloop: Check card index validity at probe — rated Moderate by Red Hat. Released 2026-09-11, updated 2026-09-14.
Affected:
No fix planned:
Out of support scope
Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-80985High· 7.0kernel: net/smc: carry oversized SMC-Rv2 LLC messages in the queue entry (CVE-2026-80985)
CVE-2026-89691High· 7.0kernel: nfsd: clear opcnt on compound arg release to prevent OOB read (CVE-2026-89691)
CVE-2026-80969Medium· 5.5kernel: ALSA: mpu401: Check card index validity at probe (CVE-2026-80969)
CVE-2026-80973High· 7.0kernel: ALSA: 6fire: bound the MIDI event length from the device (CVE-2026-80973)
CVE-2026-80976High· 7.0kernel: seg6: reset IP6CB after IPv6 decapsulation (CVE-2026-80976)
CVE-2026-89443Medium· 5.5kernel: platform/x86: ISST: Validate level in perf mask ioctls (CVE-2026-89443)