Out-of-bounds read in Linux kernel - CVE-2026-80635
Published: August 28, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to an out-of-bounds read in the wcn36xx_smd_trigger_ba_rsp function when parsing a short trigger BA firmware response. A local user can provide a crafted firmware response to cause a denial of service.
The issue occurs when candidate_cnt is at least 1 and the response does not include the required candidate structure data.
Affected software
How to mitigate CVE-2026-80635
External References
- https://git.kernel.org/stable/c/04aba50212f9f274e1a726fb3873b5ce8da2d821
- https://git.kernel.org/stable/c/af8f0ea1f0a3a5fb5ed2b8fed3f1501d644597ee
- https://git.kernel.org/stable/c/b5e6f21923ca89d90256e7346301056f6502691e
- https://git.kernel.org/stable/c/c07aa0534d50361183833e3803204044cf1d0476
- https://git.kernel.org/stable/c/d0b57bcd0dac6e2c9a3e474ec280e7db0b3edf35
- https://git.kernel.org/stable/c/d0cafe6ed8d1f6d0097eda31d85f5760d4f359c2