Executive brief
The ALSA serial-u16550 driver is a kernel audio driver used to support serial MIDI/synthesizer hardware interfaces. The driver fails to validate the device card index during probe, allowing an invalid or uninitialized index value (such as -1) to cause out-of-bounds memory access when the device is manually bound via sysfs, potentially leading to kernel crash or information disclosure.
Technical details
The vulnerability is an out-of-bounds (OOB) memory access in the ALSA serial-u16550 driver's probe function. The driver blindly trusts the devptr->id value without validating it falls within the valid card index range (0 to SNDRV_CARDS-1). When a device is manually bound via sysfs, this ID can be set to -1 (representing "none"), which bypasses normal module initialization checks. This invalid index is then used directly to access the index[] array and other parameter arrays, causing OOB read/write. The fix adds a bounds check (dev < 0 || dev >= SNDRV_CARDS) and corrects out-of-range values to 0 with a warning. No authentication or network access is required; local privileged access to sysfs is needed to trigger this.
Affected products
- Linux Linux kernel Affected across multiple versions with ALSA serial-u16550 driver (including 2.6.x through 7.x kernels prior to fix)
Timeline
- 2026-09-14: patched: Fix merged into stable kernels via commits 1cb30691dc893aafcbc1e211e94764014c0f5d12 and 41a952304cc8a308748e3f58462c879f2a9c4340
- 2026-09-11: disclosed: CVE-2026-80965 published