CVE-2026-80933

Linux · Kernel

A buffer over-read vulnerability exists in the Linux kernel mt7996 Wi-Fi driver due to improper validation of EEPROM firmware file sizes.

Executive summary

A vulnerability in the Linux kernel mt7996 driver allows a local attacker to potentially perform unauthorized memory reads or cause system instability.

Vulnerability

This is an out-of-bounds read vulnerability caused by the failure to validate the length of default EEPROM firmware files. An authenticated local user with low privileges can trigger a read beyond the firmware buffer during variant validation or copy operations.

Business impact

The vulnerability carries a CVSS score of 7.8, reflecting its potential for significant impact on system integrity and availability. While exploitation requires local access, successful triggers could lead to sensitive information disclosure from kernel memory or cause a kernel panic, resulting in system downtime. This poses a risk to environments where untrusted local users have access to kernel-level drivers.

Remediation

Immediate Action: Update the Linux kernel to version 6.18.50, 7.2.4, or later versions where the fix has been backported.

Proactive Monitoring: Monitor system logs for kernel oops or segmentation faults related to the mt76 or mt7996 wireless drivers.

Compensating Controls: Restrict access to wireless hardware configuration and driver loading modules to authorized administrative users only.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the potential for privilege escalation or system instability arising from kernel memory corruption, organizations utilizing the mt7996 wireless driver should prioritize patching. Apply the recommended kernel updates as part of the next scheduled maintenance cycle to ensure system stability and protection against local memory manipulation.

More Linux CVEs all →

History

CVE Brief tracked this CVE 1 day before it had a CVSS score.

  1. Disclosed CVE record published
  2. Collected by CVE Brief No CVSS score yet; tracked as early warning
  3. CVSS score assigned 7.8 (3.1)
  4. Analyst report written

Sources