Description
In the Linux kernel, the following vulnerability has been resolved:

ALSA: mts64: Check card index validity at probe

Although mts64 driver has a check of the given devptr->id value, it
doesn't check for a negative id, which is often given as "none" or
such value when bound via sysfs. This may lead to OOB access for
index[] and other parameters.

Add a sanity check for the card index and warn/correct it if it's a
value out of the range.
Published: 2026-09-11
Score: 4.7 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Out-of-bounds buffer access
Action: Apply patch
AI Analysis

Impact

During the probe of the ALSA mts64 driver, the driver performs a check on the devptr->id value but does not validate negative values. When a negative id is set via sysfs (for example, the string "none"), the driver may access index[] and other parameters outside their intended bounds. This out-of-bounds access could corrupt adjacent memory structures. Based on the description, this could lead to unintended modification of kernel memory, potentially causing driver failures or broader system instability when the issue is triggered. The vulnerability arises from unchecked input in the ALSA mts64 driver, allowing negative identifiers to be passed from sysfs to the probe routine.

Affected Systems

All Linux kernel versions that ship the ALSA mts64 driver without the patch are affected. Systems using those kernels and having a mts64-compatible audio device exposed through sysfs are potentially vulnerable. No.

Risk and Exploitability

The CVSS score of 4.7 indicates moderate risk while the EPSS score of < 1% suggests a low probability of exploitation under typical conditions. It is not listed in the likely local: an attacker would need permission to write to sysfs entries for the sound subsystem or otherwise trigger the probe routine. Successful exploitation could result in driver failure or, if memory corruption occurs, unspecified effects. The vulnerability does not appear to be exploitable over a network.

Generated by OpenCVE AI on September 21, 2026 at 02:26 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply a kernel release that includes the fix for the ALSA mts64 driver
  • If a kernel update cannot be performed immediately, disable or unload the mts64 kernel module to eliminate the vulnerable code path
  • Restrict write access to the sysfs entries for the mts64 device so that only privileged users can modify them

Generated by OpenCVE AI on September 21, 2026 at 02:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Mon, 14 Sep 2026 12:30:00 +0000


Sat, 12 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-787
References
Metrics threat_severity

None

cvssV3_1

{'score': 4.7, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:H'}

threat_severity

Moderate


Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: ALSA: mts64: Check card index validity at probe Although mts64 driver has a check of the given devptr->id value, it doesn't check for a negative id, which is often given as "none" or such value when bound via sysfs. This may lead to OOB access for index[] and other parameters. Add a sanity check for the card index and warn/correct it if it's a value out of the range.
Title ALSA: mts64: Check card index validity at probe
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-14T11:59:14.986Z

Reserved: 2026-08-26T14:34:25.810Z

Link: CVE-2026-80968

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:19:02.843

Modified: 2026-09-14T13:18:51.513

Link: CVE-2026-80968

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-11T19:42:32Z

Links: CVE-2026-80968 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T02:30:08Z

Weaknesses