Description
In the Linux kernel, the following vulnerability has been resolved:

wifi: mt76: fix out-of-bounds access in mmio copy helpers

mt76_mmio_write_copy() and mt76_mmio_read_copy() iterate up to
ALIGN(len, 4), so a length that is not a multiple of four reads past the
source buffer (write_copy) or writes past the destination (read_copy).
Copy the aligned body in the loop and handle the remaining tail through a
4-byte bounce buffer, keeping the register access width unchanged.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Kernel memory corruption that could enable privilege escalation
Action: Apply patch
AI Analysis

Impact

The patch addresses a bug in the mt76 Wi‑Fi driver where the copy helper functions iterated up to an aligned length rather than the actual buffer size, allowing a read or write beyond the bounds of the source or destination buffers. This behavior can corrupt kernel memory, potentially exposing sensitive data or enabling an attacker to execute arbitrary code with kernel privileges.

Affected Systems

The vulnerability is present in the Linux kernel’s mt76 Wi‑Fi driver, which is distributed with many Linux distributions. Any system running a kernel that includes the unpatched mt76 driver is affected; the specific kernel versions are not listed in the data, so all installations that have not incorporated the fix are potentially vulnerable.

Risk and Exploitability

The EPSS score is below 1 percent and the vulnerability is not listed in the CISA KEV catalog, indicating a low probability of exploitation. However, the error occurs in kernel code and could lead to memory corruption if an attacker can influence the driver’s data length calculations. Exploitation would most likely require local access or the ability to load malicious kernel modules, so the threat is moderate to high for systems that allow such access. The lack of a CVSS score in the data means the exact severity is not quantified, but the nature of the flaw suggests it could be treated as a serious kernel security issue.

Generated by OpenCVE AI on September 19, 2026 at 14:09 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Linux kernel to a version that includes the mt76_mmio_write_copy and mt76_mmio_read_copy fixes; the patch is committed in the kernel repository and can be obtained from the Git metadata links provided.
  • If an immediate kernel upgrade is not feasible, temporarily disable or unload the mt76 Wi‑Fi driver until the patch can be applied, ensuring that attackers cannot trigger the out‑of‑bounds access path.
  • Consider implementing SELinux or AppArmor policies that restrict processes from loading or communicating with the mt76 driver, thereby limiting potential privilege escalation until the kernel fix is applied.

Generated by OpenCVE AI on September 19, 2026 at 14:09 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-125
CWE-787

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: fix out-of-bounds access in mmio copy helpers mt76_mmio_write_copy() and mt76_mmio_read_copy() iterate up to ALIGN(len, 4), so a length that is not a multiple of four reads past the source buffer (write_copy) or writes past the destination (read_copy). Copy the aligned body in the loop and handle the remaining tail through a 4-byte bounce buffer, keeping the register access width unchanged.
Title wifi: mt76: fix out-of-bounds access in mmio copy helpers
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:09:10.738Z

Reserved: 2026-09-11T19:38:34.807Z

Link: CVE-2026-90369

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:36.030

Modified: 2026-09-17T17:17:36.030

Link: CVE-2026-90369

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T14:15:17Z

Weaknesses