๐Ÿ” CVE Alert

CVE-2026-80935

HIGH 8.8

wifi: mt76: mt7996: bound the device EEPROM address before the EFUSE copy

CVSS Score
8.8
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7996: bound the device EEPROM address before the EFUSE copy mt7996_mcu_get_eeprom() derives the destination of the EFUSE/EXT block copy from the address reported by the MCU response (event->addr, a device-controlled __le32) and clamps only the copy length, never the destination offset into dev->mt76.eeprom.data. A malicious or malfunctioning device can report an arbitrary address and drive an out-of-bounds write of up to MT7996_EXT_EEPROM_BLOCK_SIZE bytes past eeprom.data. Reject a response whose address would place the copy outside eeprom.data before deriving the destination pointer. Devices that echo the requested in-bounds offset are unaffected.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Sep 11, 2026
Last Updated Sep 14, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new high vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

Linux / Linux
98686cd21624c75a043e96812beadddf4f6f48e5 < 9e5abb5e2ade0b6fd0e47209711115d47a255176 98686cd21624c75a043e96812beadddf4f6f48e5 < 6be59da2063d5b3522bfde8aae0487ec095eb384 98686cd21624c75a043e96812beadddf4f6f48e5 < 13b3c29a782033ce4a230be9e5618032813dbcd4
Linux / Linux
6.2

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/9e5abb5e2ade0b6fd0e47209711115d47a255176 git.kernel.org: https://git.kernel.org/stable/c/6be59da2063d5b3522bfde8aae0487ec095eb384 git.kernel.org: https://git.kernel.org/stable/c/13b3c29a782033ce4a230be9e5618032813dbcd4