8.8

CVE-2026-80935

wifi: mt76: mt7996: bound the device EEPROM address before the EFUSE copy

In the Linux kernel, the following vulnerability has been resolved:

wifi: mt76: mt7996: bound the device EEPROM address before the EFUSE copy

mt7996_mcu_get_eeprom() derives the destination of the EFUSE/EXT block
copy from the address reported by the MCU response (event->addr, a
device-controlled __le32) and clamps only the copy length, never the
destination offset into dev->mt76.eeprom.data. A malicious or
malfunctioning device can report an arbitrary address and drive an
out-of-bounds write of up to MT7996_EXT_EEPROM_BLOCK_SIZE bytes past
eeprom.data.

Reject a response whose address would place the copy outside eeprom.data
before deriving the destination pointer. Devices that echo the requested
in-bounds offset are unaffected.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 98686cd21624c75a043e96812beadddf4f6f48e5
Version < 388f471ca4758f644394b681ce97677a4d0e772c
Status affected
Version 98686cd21624c75a043e96812beadddf4f6f48e5
Version < 9e5abb5e2ade0b6fd0e47209711115d47a255176
Status affected
Version 98686cd21624c75a043e96812beadddf4f6f48e5
Version < 6be59da2063d5b3522bfde8aae0487ec095eb384
Status affected
Version 98686cd21624c75a043e96812beadddf4f6f48e5
Version < 13b3c29a782033ce4a230be9e5618032813dbcd4
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 6.2
Status affected
Version 0
Version < 6.2
Status unaffected
Version <= 6.12.*
Version 6.12.112
Status unaffected
Version <= 6.18.*
Version 6.18.52
Status unaffected
Version <= 7.2.*
Version 7.2.4
Status unaffected
Version <= *
Version 7.3-rc1
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.22% 0.123
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 8.8 2.8 5.9
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/6be59da2063d5b3522bfde8aae0487ec095eb384
https://git.kernel.org/stable/c/13b3c29a782033ce4a230be9e5618032813dbcd4
https://git.kernel.org/stable/c/9e5abb5e2ade0b6fd0e47209711115d47a255176
https://git.kernel.org/stable/c/388f471ca4758f644394b681ce97677a4d0e772c