SB20260529156 - Integer underflow in Linux kernel mt76 mt7921 driver
Published: May 29, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Integer underflow (CVE-ID: CVE-2026-46136)
CWE-ID: CWE-191 - Integer underflow
CVSSv4: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to integer underflow in the clc buffer length handling in the mt7921 driver when retrieving the country power setting. A local user can trigger the vulnerable code path to cause a denial of service.
The issue may result in an almost infinite loop or an invalid power setting that causes driver initialization failure.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/0aa63d33742b805d1a218d18d12b983cce4b2f7b
- https://git.kernel.org/stable/c/5373f8b19e568b5c217832b9bbef165bd2b2df14
- https://git.kernel.org/stable/c/90cc573fd2f46ddbc2c329e7814b5ba3deb7b939
- https://git.kernel.org/stable/c/a0111847f0b4f6023f6dd320114697514e024ba3
- https://git.kernel.org/stable/c/e451c325b000b9a0081fd93bc6d103d6943d4b55