8.8

CVE-2026-80937

wifi: mt76: mt7915: bound the device EEPROM address before the EFUSE copy

In the Linux kernel, the following vulnerability has been resolved:

wifi: mt76: mt7915: bound the device EEPROM address before the EFUSE copy

mt7915_mcu_get_eeprom() copies a fixed EFUSE block into the driver's
dev->mt76.eeprom.data buffer at the offset reported by the MCU response
(res->addr, a device-controlled __le32) without checking it against the
buffer size. A malicious or malfunctioning device can report an arbitrary
address and drive a 16-byte out-of-bounds write past eeprom.data.

Reject a response whose address would place the copy outside eeprom.data
before deriving the destination pointer. Devices that echo the requested
in-bounds offset are unaffected.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version e57b7901469fc0b021930b83a8094baaf3d81b09
Version < 394e8cb56fc732d71041599cdb4e01f82cfd11c5
Status affected
Version e57b7901469fc0b021930b83a8094baaf3d81b09
Version < 5fdaf7016d7684ef756a229fd5d96b4a140eeb40
Status affected
Version e57b7901469fc0b021930b83a8094baaf3d81b09
Version < 5f48b0d752a76590e2c613aae5345c2474627d1b
Status affected
Version e57b7901469fc0b021930b83a8094baaf3d81b09
Version < 44b5adfe49499f53002737f5fe81d608c08122fc
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 5.8
Status affected
Version 0
Version < 5.8
Status unaffected
Version <= 6.12.*
Version 6.12.112
Status unaffected
Version <= 6.18.*
Version 6.18.50
Status unaffected
Version <= 7.2.*
Version 7.2.4
Status unaffected
Version <= *
Version 7.3-rc1
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.32% 0.245
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 8.8 2.8 5.9
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/5fdaf7016d7684ef756a229fd5d96b4a140eeb40
https://git.kernel.org/stable/c/5f48b0d752a76590e2c613aae5345c2474627d1b
https://git.kernel.org/stable/c/44b5adfe49499f53002737f5fe81d608c08122fc
https://git.kernel.org/stable/c/394e8cb56fc732d71041599cdb4e01f82cfd11c5