Description
In the Linux kernel, the following vulnerability has been resolved:

wifi: mt76: mt7996: bound the device EEPROM address before the EFUSE copy

mt7996_mcu_get_eeprom() derives the destination of the EFUSE/EXT block
copy from the address reported by the MCU response (event->addr, a
device-controlled __le32) and clamps only the copy length, never the
destination offset into dev->mt76.eeprom.data. A malicious or
malfunctioning device can report an arbitrary address and drive an
out-of-bounds write of up to MT7996_EXT_EEPROM_BLOCK_SIZE bytes past
eeprom.data.

Reject a response whose address would place the copy outside eeprom.data
before deriving the destination pointer. Devices that echo the requested
in-bounds offset are unaffected.
Published: 2026-09-11
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Kernel memory corruption via out‑of‑bounds write
Action: Apply Patch
AI Analysis

Impact

A malicious or malfunctioning Wi‑Fi device can report an arbitrary destination address for an EFUSE block copy, and the Linux kernel driver fails to limit this offset. The copy operation therefore writes up to MT7996_EXT_EEPROM_BLOCK_SIZE bytes past the driver’s internal EEPROM buffer, corrupting kernel memory. This corruption can lead to privilege escalation, arbitrary code execution or kernel panic depending on the attacker’s ability to control the data written.

Affected Systems

Linux systems that load the mt76 Wi‑Fi driver with the mt7996 controller are affected. This includes devices that use the mt7996 chipset and run a kernel image that has not incorporated the patch that bounds the EEPROM address before the copy.

Risk and Exploitability

The CVSS base score of 8.8 points to a high‑severity vulnerability, and the EPSS score of less than 1% indicates a very low likelihood of exploitation in the wild. The flaw is not listed in the CISA KEV catalog. Based on the description, the attack vector is likely a malicious EFUSE request from a compromised or rogue Wi‑Fi device that supplies an out‑of‑bounds address, which then triggers the out‑of‑bounds write and the associated kernel memory corruption.

Generated by OpenCVE AI on September 21, 2026 at 03:48 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest Linux kernel release that includes the commit of the fix that bounds the EEPROM address before the EFUSE copy (see commit 13b3c29a782033ce4a230be9e5618032813dbcd4 in the kernel source).
  • If a kernel update cannot be performed immediately, unload or disable the mt76 driver (for example, run ‘modprobe -r mt76’) so that the driver does not process EFUSE commands from potentially malicious devices.
  • Enable kernel crash dumping and monitor system logs (e.g., /var/log/kern.log) for EFUSE copy errors or out‑of‑bounds write warnings, and investigate any such incidents promptly.

Generated by OpenCVE AI on September 21, 2026 at 03:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 14 Sep 2026 12:30:00 +0000


Sun, 13 Sep 2026 06:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.4, 'vector': 'CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H'}

cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Sat, 12 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-787
References
Metrics threat_severity

None

cvssV3_1

{'score': 6.4, 'vector': 'CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H'}

threat_severity

Important


Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7996: bound the device EEPROM address before the EFUSE copy mt7996_mcu_get_eeprom() derives the destination of the EFUSE/EXT block copy from the address reported by the MCU response (event->addr, a device-controlled __le32) and clamps only the copy length, never the destination offset into dev->mt76.eeprom.data. A malicious or malfunctioning device can report an arbitrary address and drive an out-of-bounds write of up to MT7996_EXT_EEPROM_BLOCK_SIZE bytes past eeprom.data. Reject a response whose address would place the copy outside eeprom.data before deriving the destination pointer. Devices that echo the requested in-bounds offset are unaffected.
Title wifi: mt76: mt7996: bound the device EEPROM address before the EFUSE copy
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-14T11:59:01.143Z

Reserved: 2026-08-26T14:34:25.802Z

Link: CVE-2026-80935

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:18:57.403

Modified: 2026-09-14T13:18:49.783

Link: CVE-2026-80935

cve-icon Redhat

Severity : Important

Publid Date: 2026-09-11T19:42:09Z

Links: CVE-2026-80935 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T04:00:13Z

Weaknesses