# CVE-2026-80966

## Summary

- **CVE ID:** CVE-2026-80966
- **Severity:** UNKNOWN
- **CVSS Score:** 0
- **CWE:** N/A
- **Published:** Sep 11, 2026
- **Last Modified:** Sep 16, 2026

## Description

In the Linux kernel, the following vulnerability has been resolved:

ALSA: portman2x4: Check card index validity at probe

Although portman2x4 driver has a check of the given devptr->id value,
it doesn't check for a negative id, which is often given as "none" or
such value when bound via sysfs.  This may lead to OOB access for
index[] and other parameters.

Add a sanity check for the card index and warn/correct it if it's a
value out of the range.

## Affected Products

- Linux — Linux (1da177e4c3f41524e886b7f1b8a0c1fc7321cac2)
- Linux — Linux (0)
- Linux — Linux (6.12.109)
- Linux — Linux (6.18.50)
- Linux — Linux (7.2.4)
- Linux — Linux (7.3-rc1)
- Linux — Linux (757e119bf52b014b3181eed97b01f87a245b8ff9)
- Linux — Linux (2.6.21)
- Linux — Linux (5.10.270)
- Linux — Linux (5.15.221)
- Linux — Linux (6.1.188)
- Linux — Linux (6.6.157)

## References

- [CNA](https://git.kernel.org/stable/c/0ce391090809d610647f424b9b1dc24aa2c546fd)
- [CNA](https://git.kernel.org/stable/c/d7ef7890e3e35b4ba09e76fc6b72047a1599a5e8)
- [CNA](https://git.kernel.org/stable/c/e1ce8ad1009b1736b3044b3324350dcfdd516f42)
- [CNA](https://git.kernel.org/stable/c/3690ef20469d5959378260e2752f2314a2572913)
- [CNA](https://git.kernel.org/stable/c/45ea0707298798678a60ff861b695aea049a5469)
- [CNA](https://git.kernel.org/stable/c/5d7ac5e9ee5ba76b567ace13b46075caf79dcca0)
- [CNA](https://git.kernel.org/stable/c/0048994854f3e9c57b7a754de43ef8da5818d140)
- [CNA](https://git.kernel.org/stable/c/64898e9bd8b7b229efa8642b85b56b326a6ec3dc)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.21%
- **EPSS Percentile:** 11.4

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-18._