{"id":"AZL-100416","summary":"CVE-2026-80937 affecting package kernel 6.6.150.1-1","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: mt76: mt7915: bound the device EEPROM address before the EFUSE copy\n\nmt7915_mcu_get_eeprom() copies a fixed EFUSE block into the driver's\ndev-\u003emt76.eeprom.data buffer at the offset reported by the MCU response\n(res-\u003eaddr, a device-controlled __le32) without checking it against the\nbuffer size. A malicious or malfunctioning device can report an arbitrary\naddress and drive a 16-byte out-of-bounds write past eeprom.data.\n\nReject a response whose address would place the copy outside eeprom.data\nbefore deriving the destination pointer. Devices that echo the requested\nin-bounds offset are unaffected.","modified":"2026-09-12T14:15:22.781354114Z","published":"2026-09-11T20:18:57Z","upstream":["CVE-2026-80937"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-80937"}],"affected":[{"package":{"name":"kernel","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/kernel"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"6.6.150.1-1"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-100416.json"}}],"schema_version":"1.9.0"}