๐Ÿ” CVE Alert

CVE-2026-80937

HIGH 8.8

wifi: mt76: mt7915: bound the device EEPROM address before the EFUSE copy

CVSS Score
8.8
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7915: bound the device EEPROM address before the EFUSE copy mt7915_mcu_get_eeprom() copies a fixed EFUSE block into the driver's dev->mt76.eeprom.data buffer at the offset reported by the MCU response (res->addr, a device-controlled __le32) without checking it against the buffer size. A malicious or malfunctioning device can report an arbitrary address and drive a 16-byte out-of-bounds write past eeprom.data. Reject a response whose address would place the copy outside eeprom.data before deriving the destination pointer. Devices that echo the requested in-bounds offset are unaffected.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Sep 11, 2026
Last Updated Sep 13, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new high vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

Linux / Linux
e57b7901469fc0b021930b83a8094baaf3d81b09 < 5fdaf7016d7684ef756a229fd5d96b4a140eeb40 e57b7901469fc0b021930b83a8094baaf3d81b09 < 5f48b0d752a76590e2c613aae5345c2474627d1b e57b7901469fc0b021930b83a8094baaf3d81b09 < 44b5adfe49499f53002737f5fe81d608c08122fc
Linux / Linux
5.8

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/5fdaf7016d7684ef756a229fd5d96b4a140eeb40 git.kernel.org: https://git.kernel.org/stable/c/5f48b0d752a76590e2c613aae5345c2474627d1b git.kernel.org: https://git.kernel.org/stable/c/44b5adfe49499f53002737f5fe81d608c08122fc