Out-of-bounds write in Linux kernel - CVE-2026-80937
Published: September 13, 2026
Vulnerability details
The vulnerability allows an attacker with physical access to cause memory corruption.
The vulnerability exists due to an out-of-bounds write in mt7915_mcu_get_eeprom() when processing a device-controlled MCU EEPROM response. An attacker with physical access can provide a response containing an arbitrary address to cause memory corruption.