Integer underflow in Linux kernel - CVE-2026-46136
Published: May 29, 2026
Linux kernel
Detailed vulnerability description
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to integer underflow in the clc buffer length handling in the mt7921 driver when retrieving the country power setting. A local user can trigger the vulnerable code path to cause a denial of service.
The issue may result in an almost infinite loop or an invalid power setting that causes driver initialization failure.
How to mitigate CVE-2026-46136
Sources
- https://git.kernel.org/stable/c/0aa63d33742b805d1a218d18d12b983cce4b2f7b
- https://git.kernel.org/stable/c/5373f8b19e568b5c217832b9bbef165bd2b2df14
- https://git.kernel.org/stable/c/90cc573fd2f46ddbc2c329e7814b5ba3deb7b939
- https://git.kernel.org/stable/c/a0111847f0b4f6023f6dd320114697514e024ba3
- https://git.kernel.org/stable/c/e451c325b000b9a0081fd93bc6d103d6943d4b55