CVE-2026-80635

Source
https://cve.org/CVERecord?id=CVE-2026-80635
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-80635.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-80635
Downstream
Published
2026-08-28T06:48:49.637Z
Modified
2026-08-30T03:48:20.925646930Z
Severity
  • 8.8 (High) CVSS_V3 - CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
wifi: wcn36xx: fix OOB read from short trigger BA firmware response
Details

In the Linux kernel, the following vulnerability has been resolved:

wifi: wcn36xx: fix OOB read from short trigger BA firmware response

The firmware response length is only checked against sizeof(*rsp) (20 bytes), but when candidate_cnt >= 1, a 22-byte candidate struct is read at buf + 20 without verifying the response contains it. This causes an out-of-bounds read of stale heap data, corrupting the BA session state.

Add validation that the response includes the candidate data.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/80xxx/CVE-2026-80635.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
16be1ac55944412e8d132b1db26f994b368c5742
Fixed
04aba50212f9f274e1a726fb3873b5ce8da2d821
Fixed
c07aa0534d50361183833e3803204044cf1d0476
Fixed
d0b57bcd0dac6e2c9a3e474ec280e7db0b3edf35
Fixed
af8f0ea1f0a3a5fb5ed2b8fed3f1501d644597ee
Fixed
d0cafe6ed8d1f6d0097eda31d85f5760d4f359c2
Fixed
b5e6f21923ca89d90256e7346301056f6502691e

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-80635.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.7.0
Fixed
6.1.178
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.145
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.97
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.40
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.1.5

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-80635.json"