From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id E98D65678EB for ; Fri, 11 Sep 2026 19:47:14 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789156045; cv=none; b=gbSgCVvumjKvbFP48ksU7quY2iUZ520qLfqvbuhPnShoOZcYtz26/3ts4AAwU8G+QNvYAc9WMZob7UBDu/J4Dmxubv9CmCjKYHtYM4aQdxGZOwHc1qsRclSdDb75KZ7FTqdkfs0jZxcbMXLL/dxLe5Ct/zCCGbrAvqjSlavRt+U= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789156045; c=relaxed/simple; bh=02k2T5uUsibBy7xEt5WVvWeVi+fPEYe5QTqAo+07krA=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=deXLnyb81mHGdOuHOpsYhmTi810r4mw2OrTFBJ/Z61lNCy4jgdMFdkPFsSZM9qI5O1r39+xwGHXBbMk9FHbdHHbVXOMvmd8sN0kiikLp9Pi+mmN7/2iixutEjby0D/N2LMnBxhx13m5jK8sP1Vpu+wGz/zNy6vorKvaHrINUBwM= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b=jTTdHPuq; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b="jTTdHPuq" Received: by smtp.kernel.org (Postfix) with ESMTPSA id CDE5B1F0089A; Fri, 11 Sep 2026 19:47:13 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linuxfoundation.org; s=korg; t=1789156034; bh=oIqsY6lEDsKfiwPAgF2VTT6aNAhpRUOfG0cfL88DfJc=; h=From:To:Cc:Subject:Date:Reply-To; b=jTTdHPuqjOAlCN7sVnX4SskLXmm4Z3dkR3t7BBmXegFLd0xAxwhSCYfTMcWt9Jq3O 8lbHhC+CegUfMUoMwi+//V8ndtewzhJylGaNxV7t4SWA/fPKRaC7jotK4+/bHx9ak1 LsK6vTtUEwlawirP4SihNwJXF2Py5/5THUvYwASg= From: Greg Kroah-Hartman To: linux-cve-announce@vger.kernel.org Cc: Greg Kroah-Hartman Subject: CVE-2026-80966: ALSA: portman2x4: Check card index validity at probe Date: Fri, 11 Sep 2026 21:41:12 +0200 Message-ID: <2026091143-CVE-2026-80966-a226@gregkh> X-Mailer: git-send-email 2.55.0 Reply-To: , Precedence: bulk X-Mailing-List: linux-cve-announce@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 X-Developer-Signature: v=1; a=openpgp-sha256; l=2229; i=gregkh@linuxfoundation.org; h=from:subject:message-id; bh=VzCQubcP/ll3dTXQd3QcRe3Y4tdhuYJ/9p8J7+ueBwY=; b=owGbwMvMwCRo6H6F97bub03G02pJDFlLIq0377c7HcY1f1rB3s0qn/Sz9RX08wQVrTlyArmrb mj/nLisI5aFQZCJQVZMkeXLNp6j+ysOKXoZ2p6GmcPKBDKEgYtTACby5iHD/ARZY2GW9WcLer6f zvFJusT3yfKKLcOC1e4sLWml5cLuN1MF2ff5nNzFnsQEAA== X-Developer-Key: i=gregkh@linuxfoundation.org; a=openpgp; fpr=F4B60CC5BF78C2214A313DCB3147D40DDB2DFB29 Content-Transfer-Encoding: 8bit From: Greg Kroah-Hartman Description =========== In the Linux kernel, the following vulnerability has been resolved: ALSA: portman2x4: Check card index validity at probe Although portman2x4 driver has a check of the given devptr->id value, it doesn't check for a negative id, which is often given as "none" or such value when bound via sysfs. This may lead to OOB access for index[] and other parameters. Add a sanity check for the card index and warn/correct it if it's a value out of the range. The Linux kernel CVE team has assigned CVE-2026-80966 to this issue. Affected and fixed versions =========================== Fixed in 6.12.109 with commit 0ce391090809d610647f424b9b1dc24aa2c546fd Fixed in 6.18.50 with commit d7ef7890e3e35b4ba09e76fc6b72047a1599a5e8 Fixed in 7.2.4 with commit e1ce8ad1009b1736b3044b3324350dcfdd516f42 Fixed in 7.3-rc1 with commit 3690ef20469d5959378260e2752f2314a2572913 Please see https://www.kernel.org for a full list of currently supported kernel versions by the kernel community. Unaffected versions might change over time as fixes are backported to older supported kernel versions. The official CVE entry at https://cve.org/CVERecord/?id=CVE-2026-80966 will be updated if fixes are backported, please check that for the most up to date information about this issue. Affected files ============== The file(s) affected by this issue are: sound/drivers/portman2x4.c Mitigation ========== The Linux kernel CVE team recommends that you update to the latest stable kernel version for this, and many other bugfixes. Individual changes are never tested alone, but rather are part of a larger kernel release. Cherry-picking individual commits is not recommended or supported by the Linux kernel community at all. If however, updating to the latest release is impossible, the individual changes to resolve this issue can be found at these commits: https://git.kernel.org/stable/c/0ce391090809d610647f424b9b1dc24aa2c546fd https://git.kernel.org/stable/c/d7ef7890e3e35b4ba09e76fc6b72047a1599a5e8 https://git.kernel.org/stable/c/e1ce8ad1009b1736b3044b3324350dcfdd516f42 https://git.kernel.org/stable/c/3690ef20469d5959378260e2752f2314a2572913