
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-23363 is an out-of-bounds read vulnerability in the Linux kernel's mt76 wireless driver, specifically in the mt7925_mac_write_txwi_80211() function of the mt7925 component. The flaw arises from missing frame length validation before accessing management (mgmt) fields, enabling a possible out-of-bounds memory access. It was disclosed on March 25, 2026, and affects Linux kernel versions 6.7.1 through 6.12.76, 6.13 through 6.18.16, 6.19 through 6.19.6, and 7.0-rc1 through 7.0-rc2. The vulnerability carries a CVSS v3.1 base score of 7.1 (High) (Red Hat Advisory, Red Hat Bugzilla).
The root cause is classified as CWE-125 (Out-of-bounds Read) and CWE-805 (Buffer Access with Incorrect Length Value). The mt7925_mac_write_txwi_80211() function in the mt76 mt7925 Wi-Fi driver fails to validate the frame length before dereferencing management frame fields, allowing a local attacker to trigger a read beyond the intended buffer boundary. Exploitation requires local access with low privileges and no user interaction, targeting systems equipped with MediaTek mt7925 wireless hardware. Patch commits addressing the issue are available in the stable kernel tree (kernel.org patch 1, kernel.org patch 2).
A local attacker with low-privilege access on an affected system could exploit this vulnerability to read sensitive data from kernel memory (confidentiality impact) or trigger a denial-of-service condition by causing a kernel crash (availability impact). Integrity is not directly affected. The scope is limited to the local system, but kernel memory disclosure could expose credentials, cryptographic material, or other sensitive data that could facilitate further privilege escalation or lateral movement (Red Hat Advisory).
Update to a patched Linux kernel version: 6.12.77 or later, 6.18.17 or later, 6.19.7 or later, or 7.0-rc3 or later. Patch commits are available at the kernel stable tree for each affected branch. As a temporary workaround on systems where patching is not immediately feasible, restricting local user access to systems with mt7925 wireless hardware reduces exposure. SUSE has also released security updates addressing this CVE (SUSE Advisory, kernel.org patch).
Red Hat tracked the vulnerability via Bugzilla and assigned it medium severity, with the security response team monitoring the issue. SUSE issued security update announcements (SUSE-SU-2026:2217-1 and SUSE-SU-2026:2238-1) addressing the flaw in their kernel packages. The Yocto Project security mailing list also referenced the CVE. No significant public researcher commentary or social media discussion has been identified beyond standard vendor advisory channels (SUSE Advisory, Red Hat Bugzilla).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."