CVE-2026-80812
N/AIn the Linux kernel, the following vulnerability has been resolved: ALSA: dummy: Check card index validity at probe snd_dummy_probe() blindly trusts that the given devptr->id value is within the proper card index range. It's OK for the devices the driver itself creates at the module probe time, but if the device is bound manually via sysfs interface, this could be -1 as "none", and this leads to OOB access for index[] and other parameters. Add a sanity check for the card index and warn/correct it if it's a value out of the range.
No known exploitation, public exploit, or elevated probability at this time. Track for changes.
Exploitation likelihood
—EPSS not yet scored
Impact if exploited
—CVSS · not scored
- No impact metrics
Proof of concept & exploit code
- github-search Search GitHub for public PoC repos
Test against your own equipment
curl -s https://vulnpedia.com/cve/CVE-2026-80812/poc.jsonMachine-readable PoC index for this CVE (for automation).Listed for defensive triage, patch verification, and authorized testing on systems you own. Machine-readable: /cve/CVE-2026-80812/poc.json
References
Technical & other
- https://git.kernel.org/stable/c/b7579e86afcec932e169d10e2d603abed8dd2fdf
- https://git.kernel.org/stable/c/4d0892a90b57f0e89b274c3f3c51c2fa17937c88
- https://git.kernel.org/stable/c/b20eb7ecbdaa3e649023fe41b177d90983ffb487
- https://git.kernel.org/stable/c/c9f10a001c243d1f069ebb0e2f4999ad4043a254
- https://git.kernel.org/stable/c/f20c2c32ec1c5c3526f29a03b487c55a5890996c
- https://git.kernel.org/stable/c/3dba0e92e18980cb5a4d70a9a263539ae4f0c7ec
- https://git.kernel.org/stable/c/690b721b9595f9a43395fd4047a832c42b5b6078
- https://git.kernel.org/stable/c/02442d5fe8ee365a084b055d4fa81a0c1abfc3fd