CVE-2026-98159

Source
https://cve.org/CVERecord?id=CVE-2026-98159
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98159.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-98159
Downstream
Published
2026-09-25T10:36:28Z
Modified
2026-09-26T03:48:37Z
Summary
wifi: mt76: mt7921: validate CLC firmware records
Details

In the Linux kernel, the following vulnerability has been resolved:

wifi: mt76: mt7921: validate CLC firmware records

The CLC region is supplied by firmware, but the loader trusts the region count and each record length. A malformed image can make the region table pointer precede the firmware buffer, make the record loop fail to advance, or index phy->clc past its end. Validate the table and record bounds before dereferencing or copying.

Database specific
{
    "cna_assigner":  "Linux",
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/98xxx/CVE-2026-98159.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
23bdc5d8cadfc941e7782d0cb8afb2d9ae73b125
Fixed
602a950134ee2940136f60797e4457c3983b06ce
Fixed
3896be051e928c891922d91de94c99519d215dff
Fixed
3c505e2af16a9320f4355218394a955fbbc65322
Fixed
9417c5818a0146980c2608fda94c908e604eb033

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98159.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.1.0
Fixed
6.12.111
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.53
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.7

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98159.json"