CVE-2026-80933: wifi: mt76: mt7996: validate default EEPROM firmware size

Published Sep 11, 2026
·
Updated

In the Linux kernel, the following vulnerability has been resolved:

wifi: mt76: mt7996: validate default EEPROM firmware size

The default EEPROM firmware is parsed and copied as a full EEPROM without checking its length. A truncated file can make the driver read beyond the firmware buffer during variant validation or the fallback copy.

Reject files shorter than MT7996EEPROMSIZE before parsing or copying the firmware.

Affected Software

1 affected component
Linux Kernel

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Compensating control

    Ensure the driver rejects (does not parse) firmware files shorter than MT7996_EEPROM_SIZE before parsing, to prevent read beyond the firmware buffer during variant validation.

Event History

Sep 11, 2026
CVE Published
via MITRE·07:42 PM
Data Sourced
via MITRE·07:42 PM
Description

Frequently Asked Questions

1

What systems are exposed to this issue?

Systems using the Linux kernel mt76 mt7996 Wi-Fi driver may be exposed when they load a default EEPROM firmware file that is shorter than MT7996_EEPROM_SIZE.

2

What does an attacker need to exploit this vulnerability?

An attacker would need to cause the driver to use a truncated default EEPROM firmware file. The provided information does not specify how such a file could be supplied or modified.

3

How can administrators tell whether they are affected?

Check whether affected systems use the mt76 mt7996 driver and whether the default EEPROM firmware file it loads is smaller than MT7996_EEPROM_SIZE. A truncated file can trigger reads beyond the firmware buffer during variant validation or fallback copying.

4

What mitigation is available if the update cannot be applied immediately?

Ensure that any default EEPROM firmware supplied to the mt7996 driver is not truncated and is at least MT7996_EEPROM_SIZE before it is loaded.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203