Description
In the Linux kernel, the following vulnerability has been resolved:

ALSA: virmidi: Check card index validity at probe

virmidi driver blindly trusts that the given devptr->id value is
within the proper card index range at probe. It's OK for the devices
the driver itself creates at the module probe time, but if the device
is bound manually via sysfs interface, this could be -1 as "none", and
this leads to OOB access for index[] and other parameters.

Add a sanity check for the card index and warn/correct it if it's a
value out of the range.
Published: 2026-09-11
Score: 4.7 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Out-of-bounds memory access
Action: Patch Kernel
AI Analysis

Impact

The virmidi driver in the Linux kernel fails to validate the card index supplied via the sysfs interface, allowing a value of -1 to be used as a valid index. This oversight results in an out-of-bounds array access that can corrupt kernel memory or expose unintended data. The flaw is classified as CWE‑125 and can lead to kernel memory corruption or unintended information leakage.

Affected Systems

All Linux kernel builds that include the virmidi module prior to the patch are affected, meaning any system running the Linux kernel with the virmidi driver can potentially experience this issue until the kernel is upgraded to a version that implements the index sanity check.

Risk and Exploitability

The CVSS score of 4.7 indicates a low‑moderate severity. With an EPSS score of less than 1% and no listing in the CISA KEV catalogue, active exploitation is unlikely at present. An attacker would need local or privileged access to manipulate the sysfs interface and bind the device; the vulnerability does not provide a public remote attack vector.

Generated by OpenCVE AI on September 21, 2026 at 02:29 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Linux kernel to a version that includes the virmidi index‑sanity check.
  • If a kernel upgrade is not immediately available, prevent automatic loading of the virmidi module by adding a modprobe rule such as "install virmidi /bin/true" to the modprobe.d configuration.
  • Restrict sysfs access to the virmidi device by applying appropriate permission or udev rules so that only privileged users can bind or modify the device.

Generated by OpenCVE AI on September 21, 2026 at 02:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Mon, 14 Sep 2026 12:30:00 +0000


Sat, 12 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-125
References
Metrics threat_severity

None

cvssV3_1

{'score': 4.7, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:H'}

threat_severity

Moderate


Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: ALSA: virmidi: Check card index validity at probe virmidi driver blindly trusts that the given devptr->id value is within the proper card index range at probe. It's OK for the devices the driver itself creates at the module probe time, but if the device is bound manually via sysfs interface, this could be -1 as "none", and this leads to OOB access for index[] and other parameters. Add a sanity check for the card index and warn/correct it if it's a value out of the range.
Title ALSA: virmidi: Check card index validity at probe
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-14T11:59:10.730Z

Reserved: 2026-08-26T14:34:25.810Z

Link: CVE-2026-80964

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:19:02.347

Modified: 2026-09-14T13:18:51.003

Link: CVE-2026-80964

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-11T19:42:29Z

Links: CVE-2026-80964 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T02:30:08Z

Weaknesses