Linux Kernel Vulnerability in mt76 Wi-Fi Driver Affecting Firmware Management
CVE-2026-98159
What is CVE-2026-98159?
A vulnerability exists in the mt76 Wi-Fi driver of the Linux kernel where the firmware loader fails to adequately validate CLC region records provided by firmware. This oversight can lead to improper dereferencing of pointers, resulting in potential buffer overflows or corruption. Specifically, a malformed firmware image may cause record indexing errors, allowing exploiters to manipulate memory access. It is critical for users relying on this driver to ensure their systems are updated to mitigate associated risks.
Affected Version(s)
Linux 23bdc5d8cadfc941e7782d0cb8afb2d9ae73b125 < 602a950134ee2940136f60797e4457c3983b06ce
Linux 23bdc5d8cadfc941e7782d0cb8afb2d9ae73b125 < 3896be051e928c891922d91de94c99519d215dff
Linux 23bdc5d8cadfc941e7782d0cb8afb2d9ae73b125 < 3c505e2af16a9320f4355218394a955fbbc65322