ALSA: aloop: Check card index validity at probe
Published Sep 11, 2026
5.5
MEDIUMCVSS 3.1
EPSS 0.17%
Description
aloop driver blindly trusts that the given devptr->id value is within the proper card index range at probe. It's OK for the devices the driver itself creates at the module probe time, but if the device is bound manually via sysfs interface, this could be -1 as "none", and this leads to OOB access for index[] and other parameters.
Add a sanity check for the card index and warn/correct it if it's a value out of the range.
Affected products
-
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version
-
- Version 2.6.37StatusaffectedConstraints-
- Version 0StatusunaffectedConstraints<2.6.37
- Version 5.15.221StatusunaffectedConstraints<=5.15.*
- Version 6.1.188StatusunaffectedConstraints<=6.1.*
- Version 6.12.109StatusunaffectedConstraints<=6.12.*
- Version 6.18.50StatusunaffectedConstraints<=6.18.*
- Version 6.6.157StatusunaffectedConstraints<=6.6.*
- Version 7.2.4StatusunaffectedConstraints<=7.2.*
- Version 7.3-rc1StatusunaffectedConstraints<=*
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Linux | Linux | unaffected |
| ||||||||||||||||||||||||||||||
| Linux | Linux | affected |
|
No data.
No data.
Red Hat Enterprise Linux 10
kernel
Fix deferred
Red Hat Enterprise Linux 10
kernel-rt
Fix deferred
Red Hat Enterprise Linux 6
kernel
Out of support scope
Red Hat Enterprise Linux 7
kernel
Fix deferred
Red Hat Enterprise Linux 7
kernel-rt
Fix deferred
Red Hat Enterprise Linux 8
kernel
Fix deferred
Red Hat Enterprise Linux 8
kernel-rt
Fix deferred
Red Hat Enterprise Linux 9
kernel
Fix deferred
Red Hat Enterprise Linux 9
kernel-rt
Fix deferred
Red Hat OpenShift Container Platform 4
openshift/ose-rhel-coreos-8
Fix deferred
Red Hat OpenShift Container Platform 4
openshift/ose-rhel-coreos-9
Fix deferred
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | kernel | Fix deferred | n/a |
| Red Hat Enterprise Linux 10 | kernel-rt | Fix deferred | n/a |
| Red Hat Enterprise Linux 6 | kernel | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | kernel | Fix deferred | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Fix deferred | n/a |
| Red Hat Enterprise Linux 8 | kernel | Fix deferred | n/a |
| Red Hat Enterprise Linux 8 | kernel-rt | Fix deferred | n/a |
| Red Hat Enterprise Linux 9 | kernel | Fix deferred | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Fix deferred | n/a |
| Red Hat OpenShift Container Platform 4 | openshift/ose-rhel-coreos-8 | Fix deferred | n/a |
| Red Hat OpenShift Container Platform 4 | openshift/ose-rhel-coreos-9 | Fix deferred | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (13)
- https://access.redhat.com/security/cve/CVE-2026-80972 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2532492 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-76295 Advisory
- https://git.kernel.org/pub/scm/linux/security/vulns.git/plain/cve/published/2026/CVE-2026-80972.mbox
- https://git.kernel.org/stable/c/6da6ffb34a5d54e7e6efebb253899c6a3501a611
- https://git.kernel.org/stable/c/6fe7d13608a9d1cf5aff9decc0cc653b0f38f537
- https://git.kernel.org/stable/c/7b3f9855849363e402bf2141df2b428581cbf31b
- https://git.kernel.org/stable/c/819b106a9fd2ef3fd8abf898b9a8e4524eca8f48
- https://git.kernel.org/stable/c/c589aeaadfde1cfedb5c6f0a3c782807282126d9
- https://git.kernel.org/stable/c/e35d11102ef0945feaa1dba4e511685911695ab9
- https://git.kernel.org/stable/c/efbc2e9e43a1b5c6d75ae47439c06896bb142ae6
- https://nvd.nist.gov/vuln/detail/CVE-2026-80972
- https://www.cve.org/CVERecord?id=CVE-2026-80972
Change history (0)
No recorded changes yet.