CVE-2026-80812Hinoki check available

Unspecified impact via unchecked card index

Published Sep 4, 2026 · Updated Sep 4, 2026

Out-of-bounds access in the ALSA dummy driver in Linux allows local users to cause unspecified impact through a manual sysfs bind. The snd_dummy_probe() function uses devptr->id, including the -1 "none" value, to index index[] and other parameter arrays without first validating the card-number range. Triggering requires manual driver binding through sysfs; the published record does not establish a crash, disclosure, corruption, or privilege gain.

CVSS severityUnavailable
Unscored
EPSS probability0.18%
Next 30 days · Sep 16, 2026
Known exploitationUnconfirmed
Based on sourced intelligence
Hinoki checkAvailable
Coverage for this vulnerability

See if you're affected

Explore vulnerability checks for your environment with Hinoki.

Book a demo

Summary

What happened

Out-of-bounds access in the ALSA dummy driver in Linux allows local users to cause unspecified impact through a manual sysfs bind. The snd_dummy_probe() function uses devptr->id, including the -1 "none" value, to index index[] and other parameter arrays without first validating the card-number range. Triggering requires manual driver binding through sysfs; the published record does not establish a crash, disclosure, corruption, or privilege gain.

The record

CVE
CVE-2026-80812
Published
Sep 4, 2026
Updated
Sep 4, 2026
Vendor
The Linux Kernel Organization
Product
Linux
Classifications
CWE-125
Attack vector
local
Privileges
Unavailable

Timeline

How it unfolded

  1. Sep 4, 2026CVE publishedPublication date reported by the CVE source.
  2. Sep 4, 2026Record updatedLatest update available in the CVE record.

Exploitability

Present is not the same as exploitable

Compare your product and version with the public record. A matching version still requires validation against your environment.

Is a vulnerable build present?

Compare these published version ranges with your installed build and any vendor patches.

  1. Affected versionversion=0 <5.15.218
  2. Affected versionversion=0 <6.1.185
  3. Affected versionversion=0 <6.12.106
  4. Affected versionversion=0 <6.18.47
  5. Affected versionversion=0 <6.6.154
  6. Affected versionversion=0 <7.1.11
  7. Affected versionversion=0 <7.2.1
  8. Affected versionversion=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <02442d5fe8ee365a084b055d4fa81a0c1abfc3fd
  9. Affected versionversion=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <3dba0e92e18980cb5a4d70a9a263539ae4f0c7ec
  10. Affected versionversion=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <4d0892a90b57f0e89b274c3f3c51c2fa17937c88
  11. Affected versionversion=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <690b721b9595f9a43395fd4047a832c42b5b6078
  12. Affected versionversion=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <b20eb7ecbdaa3e649023fe41b177d90983ffb487
  13. Affected versionversion=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <b7579e86afcec932e169d10e2d603abed8dd2fdf
  14. Affected versionversion=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <c9f10a001c243d1f069ebb0e2f4999ad4043a254
  15. Affected versionversion=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <f20c2c32ec1c5c3526f29a03b487c55a5890996c

What conditions does exploitation require?

Attack vectorlocal
Required privilegesUnavailable in this record.

What is affected?

The Linux Kernel Organization · Linuxversion=0 <5.15.218; version=0 <6.1.185; version=0 <6.12.106; version=0 <6.18.47; version=0 <6.6.154; version=0 <7.1.11; version=0 <7.2.1; version=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <02442d5fe8ee365a084b055d4fa81a0c1abfc3fd; version=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <3dba0e92e18980cb5a4d70a9a263539ae4f0c7ec; version=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <4d0892a90b57f0e89b274c3f3c51c2fa17937c88; version=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <690b721b9595f9a43395fd4047a832c42b5b6078; version=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <b20eb7ecbdaa3e649023fe41b177d90983ffb487; version=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <b7579e86afcec932e169d10e2d603abed8dd2fdf; version=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <c9f10a001c243d1f069ebb0e2f4999ad4043a254; version=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <f20c2c32ec1c5c3526f29a03b487c55a5890996c

Published CVSS scores

No CVSS assessment is available in this record.

CVSS describes severity. EPSS estimates exploitation probability.

Attacks

What attackers are doing with it

Daily unique IPs observed by Shadowserver honeypots for known exploited vulnerabilities (KEVs). Missing observations do not establish an absence of attacks.

Daily unique IPsNo honeypot observations are available for this CVE in the selected window.

No observations available

Sep 10, 2026Sep 16, 2026
Latest reporting daySep 16, 2026
Latest daily unique IPsUnavailable
Prior 30-day averageUnavailable
SourceShadowserver honeypots (KEV)
Vectorlocal
PrivilegesUnavailable
Known exploitationUnconfirmed
Public exploitUnconfirmed

Weakness, pattern, technique

CWE-125Out-of-bounds Read

Public exploit references

No public exploit references are available in this record.

Labels summarize the accepted research assessment. They do not indicate a test against your environment.

Technologies

Your stack

See the directory against your own environment.

Your stack

Check the software in your environment

Book a demo to see how Hinoki identifies affected software and validates exploitability in your environment.

Book a demo