Description
In the Linux kernel, the following vulnerability has been resolved:

wifi: mt76: mt7915: bound the device EEPROM address before the EFUSE copy

mt7915_mcu_get_eeprom() copies a fixed EFUSE block into the driver's
dev->mt76.eeprom.data buffer at the offset reported by the MCU response
(res->addr, a device-controlled __le32) without checking it against the
buffer size. A malicious or malfunctioning device can report an arbitrary
address and drive a 16-byte out-of-bounds write past eeprom.data.

Reject a response whose address would place the copy outside eeprom.data
before deriving the destination pointer. Devices that echo the requested
in-bounds offset are unaffected.
Published: 2026-09-11
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote code execution via kernel driver
Action: Immediate Patch
AI Analysis

Impact

The Wi‑Fi driver mt76/mt7915 performs an EFUSE copy into an internal EEPROM buffer using an offset supplied by the device firmware, without validating that malicious or malfunctioning device can report an address that causes a 16‑byte out‑of‑bounds write, corrupting kernel memory. If the write corrupts critical data structures or function pointers, an attacker could achieve arbitrary code execution at the kernel privilege level. The vulnerability is therefore a kernel memory corruption flaw with potential for privilege escalation.

Affected Systems

Linux kernel builds that include the mt76/mt7915 Wi‑Fi driver. The advisory applies to all versions that have not yet integrated the fix.

Risk and Exploitability

The flaw allows an attacker controlling the Wi‑Fi adapter firmware to supply an arbitrary offset. The driver copies a fixed EFUSE block into its eeprom.data buffer at the reported offset without validating bounds, which results in a 16‑byte out‑of‑bounds write. EPSS probability (<1 %). The CVSS score of 8.8‑level code execution. The vulnerability is not listed in CISA KEV.

Generated by OpenCVE AI on September 21, 2026 at 03:47 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Linux kernel to a release that includes the bound check for the only definitive remedy to eliminate the out‑of‑bounds write.
  • If an updated kernel cannot be applied immediately, shut down or disable the affected mt7915 wireless interface on critical hosts to remove the attack surface. This limits the driver’s ability to process EFUSE commands from untrusted Wi‑Fi adapters.
  • Enable investigate suspicious EFUSE or EFUSE copy events that may indicate exploitation attempts.

Generated by OpenCVE AI on September 21, 2026 at 03:47 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 13 Sep 2026 06:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.8, 'vector': 'CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H'}

cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Sat, 12 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-787
References
Metrics threat_severity

None

cvssV3_1

{'score': 6.8, 'vector': 'CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H'}

threat_severity

Important


Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7915: bound the device EEPROM address before the EFUSE copy mt7915_mcu_get_eeprom() copies a fixed EFUSE block into the driver's dev->mt76.eeprom.data buffer at the offset reported by the MCU response (res->addr, a device-controlled __le32) without checking it against the buffer size. A malicious or malfunctioning device can report an arbitrary address and drive a 16-byte out-of-bounds write past eeprom.data. Reject a response whose address would place the copy outside eeprom.data before deriving the destination pointer. Devices that echo the requested in-bounds offset are unaffected.
Title wifi: mt76: mt7915: bound the device EEPROM address before the EFUSE copy
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-13T06:28:17.643Z

Reserved: 2026-08-26T14:34:25.803Z

Link: CVE-2026-80937

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:18:57.627

Modified: 2026-09-13T07:17:01.423

Link: CVE-2026-80937

cve-icon Redhat

Severity : Important

Publid Date: 2026-09-11T19:42:10Z

Links: CVE-2026-80937 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T04:00:13Z

Weaknesses