VDB

CVE-2026-80968

CVE-2026-80968 PUBLISHED

Reported by Linux · Published September 11, 2026

In the Linux kernel, the following vulnerability has been resolved: ALSA: mts64: Check card index validity at probe Although mts64 driver has a check of the given devptr->id value, it doesn't check for a negative id, which is often given as "none" or such value when bound via sysfs. This may lead to OOB access for index[] and other parameters. Add a sanity check for the card index and warn/correct it if it's a value out of the range.

EPSS 0.21% · 11.6th percentile

Risk Scores

EPSS Score
0.21%
11.6th percentile

Affected Products

VendorProductVersions
LinuxLinux68ab801e32bbe2caac8b8c6e6e94f41fe7d687ad, 68ab801e32bbe2caac8b8c6e6e94f41fe7d687ad, 68ab801e32bbe2caac8b8c6e6e94f41fe7d687ad
LinuxLinux2.6.19, 0, 5.10.270
linuxlinux_kernel0, 0, 0
LinuxLinux1da177e4c3f41524e886b7f1b8a0c1fc7321cac2, 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2, 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2

Timeline

  • Sep 11, 2026 CVE Published
  • Sep 12, 2026 EPSS Score
  • Sep 12, 2026 Coalition ESS Score
  • Sep 14, 2026 CVE Updated
  • Sep 15, 2026 EPSS Score
  • Sep 18, 2026 EPSS Score

References

Open in Interactive Console →
$ Console Community · 100/wk Open console ›