# CVE-2026-80968

## Summary

- **CVE ID:** CVE-2026-80968
- **Severity:** UNKNOWN
- **CVSS Score:** 0
- **CWE:** N/A
- **Published:** Sep 11, 2026
- **Last Modified:** Sep 16, 2026

## Description

In the Linux kernel, the following vulnerability has been resolved:

ALSA: mts64: Check card index validity at probe

Although mts64 driver has a check of the given devptr->id value, it
doesn't check for a negative id, which is often given as "none" or
such value when bound via sysfs.  This may lead to OOB access for
index[] and other parameters.

Add a sanity check for the card index and warn/correct it if it's a
value out of the range.

## Affected Products

- Linux — Linux (1da177e4c3f41524e886b7f1b8a0c1fc7321cac2)
- Linux — Linux (0)
- Linux — Linux (6.12.109)
- Linux — Linux (6.18.50)
- Linux — Linux (7.2.4)
- Linux — Linux (7.3-rc1)
- Linux — Linux (68ab801e32bbe2caac8b8c6e6e94f41fe7d687ad)
- Linux — Linux (2.6.19)
- Linux — Linux (5.10.270)
- Linux — Linux (5.15.221)
- Linux — Linux (6.1.188)
- Linux — Linux (6.6.157)

## References

- [CNA](https://git.kernel.org/stable/c/036e7aa793375ab16ea0f64b8de6673220416cc1)
- [CNA](https://git.kernel.org/stable/c/a4e774eeb61aec64da5b03d3becffde26f7fe4de)
- [CNA](https://git.kernel.org/stable/c/cf3af453a48c8d905512dfc44a5a59439b70f4f0)
- [CNA](https://git.kernel.org/stable/c/d18a260720f86a5f8b5fcfefc4ba2e9dd01c10f8)
- [CNA](https://git.kernel.org/stable/c/1566ca99fc0e892b9164ad893d268b00064fff54)
- [CNA](https://git.kernel.org/stable/c/5d986d8c9e616636032636d99133f2535f94300d)
- [CNA](https://git.kernel.org/stable/c/5168a6241e953ecadb0ec05609649f6a7367fef8)
- [CNA](https://git.kernel.org/stable/c/9cd7c59a106e7267d0cbcf68670594584d8689d0)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.21%
- **EPSS Percentile:** 11.5

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-18._