CVE-2026-80635
EUVD-2026-6751128.08.2026, 08:16
In the Linux kernel, the following vulnerability has been resolved: wifi: wcn36xx: fix OOB read from short trigger BA firmware response The firmware response length is only checked against sizeof(*rsp) (20 bytes), but when candidate_cnt >= 1, a 22-byte candidate struct is read at buf + 20 without verifying the response contains it. This causes an out-of-bounds read of stale heap data, corrupting the BA session state. Add validation that the response includes the candidate data.Enginsight
Awaiting analysis
This vulnerability is currently awaiting analysis.
Debian Releases
Vulnerability Media Exposure
References