Description
In the Linux kernel, the following vulnerability has been resolved:

ALSA: mpu401: Check card index validity at probe

mpu401 driver blindly trusts that the given devptr->id value is within
the proper card index range at probe. It's OK for the devices the
driver itself creates at the module probe time, but if the device is
bound manually via sysfs interface, this could be -1 as "none", and
this leads to OOB access for index[] and other parameters.

Add a sanity check for the card index and warn/correct it if it's a
value out of the range.
Published: 2026-09-11
Score: 4.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Out-of-bounds read leading to potential denial of service
Action: Apply Patch
AI Analysis

Impact

The ALSA mpu401 driver in the Linux kernel assumes the device pointer’s id field is always a valid index during probe. When a driver is manually bound through the sysfs interface, the id may be set to –1 to indicate ‘none’, which causes the driver to access an array outside its bounds, potentially corrupting memory or crashing the kernel. This flaw is a classic out‑of-bounds read (CWE‑125) and does not directly result in code execution but can destabilize the system or leak sensitive data.

Affected Systems

All Linux kernel builds that include the unpatched mpu401 ALSA driver, including default distributions and custom in‑tree kernels, are affected until the fix that checks the card index and corrects invalid values is applied.

Risk and Exploitability

The CVSS score of 4.1 classifies the vulnerability as low severity, and the EPSS score of less than 1 % indicates a low probability of exploitation. It is not listed in the CISA KEV catalog. The exploit requires local file system write access to the sysfs binding interface, making the attack vector local. An attacker with such privileges can trigger the out‑of‑bounds read, potentially causing a denial of service or accessing kernel memory.

Generated by OpenCVE AI on September 21, 2026 at 02:25 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the kernel to a version that includes the patch which adds a sanity check for the mpu401 ALSA sysfs entries so that only privileged users can bind devices.
  • If the mpu401 device is not required, blacklist or disable the driver to prevent manual binding through sysfs.
  • Configure the system so that only authorized users can write to the ALSA sysfs interfaces (e.g., by setting appropriate ACLs on /sys/class/sound or /dev/snd entries).

Generated by OpenCVE AI on September 21, 2026 at 02:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Mon, 14 Sep 2026 12:30:00 +0000


Sat, 12 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-125
References
Metrics threat_severity

None

cvssV3_1

{'score': 4.1, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H'}

threat_severity

Moderate


Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: ALSA: mpu401: Check card index validity at probe mpu401 driver blindly trusts that the given devptr->id value is within the proper card index range at probe. It's OK for the devices the driver itself creates at the module probe time, but if the device is bound manually via sysfs interface, this could be -1 as "none", and this leads to OOB access for index[] and other parameters. Add a sanity check for the card index and warn/correct it if it's a value out of the range.
Title ALSA: mpu401: Check card index validity at probe
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-14T11:59:16.085Z

Reserved: 2026-08-26T14:34:25.810Z

Link: CVE-2026-80969

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:19:02.967

Modified: 2026-09-14T13:18:51.643

Link: CVE-2026-80969

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-11T19:42:33Z

Links: CVE-2026-80969 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T02:30:08Z

Weaknesses