---
id: CVE-2026-80933
title: >-
  kernel: wifi: mt76: mt7996: validate default EEPROM firmware size
  (CVE-2026-80933)
summary: >-
  A flaw was found in the Linux kernel's mt76: mt7996 Wi-Fi driver. This
  vulnerability occurs because the driver does not properly validate the size of
  the default EEPROM (Electrically Erasable Programmable Read-Only Memory)
  firmware. A spec…
severity: medium
cvss: 5.5
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'
cvssSource: vendor
cwe: CWE-125
vendor: Red Hat
product: Linux
affected:
  - >-
    Linux >= 98686cd21624c75a043e96812beadddf4f6f48e5 <
    b4bf67cc0871b13103c404b38e332b9d4403a0da
  - >-
    Linux >= 98686cd21624c75a043e96812beadddf4f6f48e5 <
    127a291f4c8069a4e71906938402cacfe24ee8cd
  - >-
    Linux >= 98686cd21624c75a043e96812beadddf4f6f48e5 <
    03b81f015dbb29807ce1ec6d45537d658abdac69
  - >-
    Linux >= 98686cd21624c75a043e96812beadddf4f6f48e5 <
    7074ec3769820302f1ccf8794a40a6582153b820
  - >-
    Linux >= 98686cd21624c75a043e96812beadddf4f6f48e5 <
    653c6e289b13cc6942f3e8f8e3c568e70fa42d1f
  - Linux 6.2
published: '2026-09-11'
updated: '2026-09-14'
sourceUpdated: '2026-09-14T14:48:19+00:00'
source: CSAF
sourceUrl: 'https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-80933.json'
references:
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-80933.json
  - url: 'https://access.redhat.com/security/cve/CVE-2026-80933'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2532333'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-80933'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-80933'
  - url: >-
      https://git.kernel.org/pub/scm/linux/security/vulns.git/plain/cve/published/2026/CVE-2026-80933.mbox
  - url: 'https://git.kernel.org/stable/c/b4bf67cc0871b13103c404b38e332b9d4403a0da'
  - url: 'https://git.kernel.org/stable/c/127a291f4c8069a4e71906938402cacfe24ee8cd'
  - url: 'https://git.kernel.org/stable/c/03b81f015dbb29807ce1ec6d45537d658abdac69'
  - url: 'https://git.kernel.org/stable/c/7074ec3769820302f1ccf8794a40a6582153b820'
  - url: 'https://git.kernel.org/stable/c/653c6e289b13cc6942f3e8f8e3c568e70fa42d1f'
tags:
  - csaf
  - vex
  - red-hat
  - cve.org
  - score-dispute
epss: 0.00128
epssPercentile: 0.02846
scores:
  vendor: 5.5
  cna: 7.8
ingestedAt: '2026-09-14T15:23:07.455Z'
---

## Overview

A flaw was found in the Linux kernel's mt76: mt7996 Wi-Fi driver. This vulnerability occurs because the driver does not properly validate the size of the default EEPROM (Electrically Erasable Programmable Read-Only Memory) firmware. A specially crafted, truncated EEPROM firmware file can cause the driver to read beyond its allocated buffer, potentially leading to information disclosure or a denial of service.

## Vendor advisories

- **Red Hat VEX** · Moderate · updated 2026-09-14 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-80933.json)

**kernel: wifi: mt76: mt7996: validate default EEPROM firmware size** — rated Moderate by Red Hat. Released 2026-09-11, updated 2026-09-14.

Not affected:

- Red Hat Enterprise Linux 10
- Red Hat Enterprise Linux 6
- Red Hat Enterprise Linux 7
- Red Hat Enterprise Linux 8
- Red Hat Enterprise Linux 9
- Red Hat OpenShift Container Platform 4

## Remediation

Refer to the advisory for fix availability.
