Incorrect Calculation of Buffer Size in Linux kernel - CVE-2026-80825
Published: September 5, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper handling of packet buffer headroom in mt7925_usb_sdio_tx_prepare_skb() when forwarding frames from a bridged wired interface to an mt7925u access point. A remote attacker can send a frame that is forwarded through the bridge to cause a denial of service.
Affected software
How to mitigate CVE-2026-80825
External References
- https://git.kernel.org/stable/c/22edb6786127271aeba7abd30f152977c605c6a3
- https://git.kernel.org/stable/c/8d481f93588932a95f657671d4e1601b90d130cc
- https://git.kernel.org/stable/c/9a72b180f0575e41471e088e09bddc4b73d6dee2
- https://git.kernel.org/stable/c/e5e8fc11a7ac578f16079f855b7fffc1649d053c
- https://git.kernel.org/stable/c/ef3e34874d2332d0f63e72c2c35ce5c93568c125