CVE-2026-80973High· 7.0▾ TwilightA flaw was found in the Linux kernel's ALSA (Advanced Linux Sound Architecture) subsystem, specifically within the 6fire driver. This vulnerability allows a malicious USB device to trigger an out-of-bounds read by sending a specially craft…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 38.5 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 12.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via CSAF
0.2%
— → 6.3
none → medium
Last analysed / modified upstream
— → 7
none → high
0.2% → 0.2%
A flaw was found in the Linux kernel's ALSA (Advanced Linux Sound Architecture) subsystem, specifically within the 6fire driver. This vulnerability allows a malicious USB device to trigger an out-of-bounds read by sending a specially crafted MIDI event with an excessive length. This can lead to the disclosure of sensitive information from kernel memory. The issue can be triggered upon device connection without requiring user interaction, provided a MIDI input substream is open.
kernel: ALSA: 6fire: bound the MIDI event length from the device — rated Moderate by Red Hat. Released 2026-09-11, updated 2026-09-14.
Affected:
No fix planned:
Out of support scope
Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-80985High· 7.0kernel: net/smc: carry oversized SMC-Rv2 LLC messages in the queue entry (CVE-2026-80985)
CVE-2026-89691High· 7.0kernel: nfsd: clear opcnt on compound arg release to prevent OOB read (CVE-2026-89691)
CVE-2026-80969Medium· 5.5kernel: ALSA: mpu401: Check card index validity at probe (CVE-2026-80969)
CVE-2026-80972Medium· 5.5kernel: ALSA: aloop: Check card index validity at probe (CVE-2026-80972)
CVE-2026-80976High· 7.0kernel: seg6: reset IP6CB after IPv6 decapsulation (CVE-2026-80976)
CVE-2026-89443Medium· 5.5kernel: platform/x86: ISST: Validate level in perf mask ioctls (CVE-2026-89443)