CVE-2026-80935
Received Received - Intake

Buffer Overflow in MediaTek MT7996 WiFi Driver

Vulnerability report for CVE-2026-80935, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-11

Last updated on: 2026-09-14

Assigner: kernel.org

Description

In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7996: bound the device EEPROM address before the EFUSE copy mt7996_mcu_get_eeprom() derives the destination of the EFUSE/EXT block copy from the address reported by the MCU response (event->addr, a device-controlled __le32) and clamps only the copy length, never the destination offset into dev->mt76.eeprom.data. A malicious or malfunctioning device can report an arbitrary address and drive an out-of-bounds write of up to MT7996_EXT_EEPROM_BLOCK_SIZE bytes past eeprom.data. Reject a response whose address would place the copy outside eeprom.data before deriving the destination pointer. Devices that echo the requested in-bounds offset are unaffected.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-11
Last Modified
2026-09-14
Generated
2026-10-02
AI Q&A
2026-09-12
EPSS Evaluated
2026-10-01
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
linux linux_kernel *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a vulnerability in the Linux kernel affecting the mt76 driver for MediaTek MT7996 WiFi devices. It allows a malicious or malfunctioning device to write up to 4096 bytes past the end of a buffer in kernel memory by reporting an arbitrary address for an EEPROM copy operation. The issue occurs because the code only checks the length of the copy but not the destination address.

Detection Guidance

This vulnerability affects the Linux kernel's mt76 driver for MediaTek MT7996 WiFi devices. Detection requires checking kernel logs for out-of-bounds write attempts or unusual EEPROM access patterns. Monitor dmesg for errors related to mt76 or mt7996 drivers. No specific commands are provided in the context.

Impact Analysis

This vulnerability could allow an attacker with access to a vulnerable WiFi device to crash the system, execute arbitrary code in the kernel, or escalate privileges. It may lead to denial of service or compromise of the affected device running the Linux kernel with the mt76 driver.

Compliance Impact

This vulnerability could potentially lead to unauthorized memory access or corruption, which may impact data integrity and confidentiality. For standards like GDPR or HIPAA, such issues could result in non-compliance if they lead to data breaches or unauthorized access to sensitive information. However, specific compliance impacts depend on system configuration and deployment.

Mitigation Strategies

Update the Linux kernel to a patched version that includes the fix for CVE-2026-80935. If immediate patching is not possible, disable the affected mt76/mt7996 WiFi driver or restrict access to untrusted devices until the update is applied.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-80935. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart