CVE-2026-80933
wifi: mt76: mt7996: validate default EEPROM firmware size
CVSS Score
7.8
EPSS Score
0.0%
EPSS Percentile
0th
In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7996: validate default EEPROM firmware size The default EEPROM firmware is parsed and copied as a full EEPROM without checking its length. A truncated file can make the driver read beyond the firmware buffer during variant validation or the fallback copy. Reject files shorter than MT7996_EEPROM_SIZE before parsing or copying the firmware.
| Vendor | linux |
| Product | linux |
| Ecosystems | |
| Industries | Technology |
| Published | Sep 11, 2026 |
| Last Updated | Sep 14, 2026 |
Stay Ahead of the Next One
Get instant alerts for linux linux
Be the first to know when new high vulnerabilities affecting linux linux are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Affected Versions
Linux / Linux
98686cd21624c75a043e96812beadddf4f6f48e5 < b4bf67cc0871b13103c404b38e332b9d4403a0da 98686cd21624c75a043e96812beadddf4f6f48e5 < 127a291f4c8069a4e71906938402cacfe24ee8cd 98686cd21624c75a043e96812beadddf4f6f48e5 < 03b81f015dbb29807ce1ec6d45537d658abdac69 98686cd21624c75a043e96812beadddf4f6f48e5 < 7074ec3769820302f1ccf8794a40a6582153b820 98686cd21624c75a043e96812beadddf4f6f48e5 < 653c6e289b13cc6942f3e8f8e3c568e70fa42d1f
Linux / Linux
6.2
References
git.kernel.org: https://git.kernel.org/stable/c/b4bf67cc0871b13103c404b38e332b9d4403a0da git.kernel.org: https://git.kernel.org/stable/c/127a291f4c8069a4e71906938402cacfe24ee8cd git.kernel.org: https://git.kernel.org/stable/c/03b81f015dbb29807ce1ec6d45537d658abdac69 git.kernel.org: https://git.kernel.org/stable/c/7074ec3769820302f1ccf8794a40a6582153b820 git.kernel.org: https://git.kernel.org/stable/c/653c6e289b13cc6942f3e8f8e3c568e70fa42d1f