CVE-2026-23363
Linux Kernel vulnerability analysis and mitigation

Overview

CVE-2026-23363 is an out-of-bounds read vulnerability in the Linux kernel's mt76 wireless driver, specifically in the mt7925_mac_write_txwi_80211() function of the mt7925 component. The flaw arises from missing frame length validation before accessing management (mgmt) fields, enabling a possible out-of-bounds memory access. It was disclosed on March 25, 2026, and affects Linux kernel versions 6.7.1 through 6.12.76, 6.13 through 6.18.16, 6.19 through 6.19.6, and 7.0-rc1 through 7.0-rc2. The vulnerability carries a CVSS v3.1 base score of 7.1 (High) (Red Hat Advisory, Red Hat Bugzilla).

Technical details

The root cause is classified as CWE-125 (Out-of-bounds Read) and CWE-805 (Buffer Access with Incorrect Length Value). The mt7925_mac_write_txwi_80211() function in the mt76 mt7925 Wi-Fi driver fails to validate the frame length before dereferencing management frame fields, allowing a local attacker to trigger a read beyond the intended buffer boundary. Exploitation requires local access with low privileges and no user interaction, targeting systems equipped with MediaTek mt7925 wireless hardware. Patch commits addressing the issue are available in the stable kernel tree (kernel.org patch 1, kernel.org patch 2).

Impact

A local attacker with low-privilege access on an affected system could exploit this vulnerability to read sensitive data from kernel memory (confidentiality impact) or trigger a denial-of-service condition by causing a kernel crash (availability impact). Integrity is not directly affected. The scope is limited to the local system, but kernel memory disclosure could expose credentials, cryptographic material, or other sensitive data that could facilitate further privilege escalation or lateral movement (Red Hat Advisory).

Mitigation and workarounds

Update to a patched Linux kernel version: 6.12.77 or later, 6.18.17 or later, 6.19.7 or later, or 7.0-rc3 or later. Patch commits are available at the kernel stable tree for each affected branch. As a temporary workaround on systems where patching is not immediately feasible, restricting local user access to systems with mt7925 wireless hardware reduces exposure. SUSE has also released security updates addressing this CVE (SUSE Advisory, kernel.org patch).

Community reactions

Red Hat tracked the vulnerability via Bugzilla and assigned it medium severity, with the security response team monitoring the issue. SUSE issued security update announcements (SUSE-SU-2026:2217-1 and SUSE-SU-2026:2238-1) addressing the flaw in their kernel packages. The Yocto Project security mailing list also referenced the CVE. No significant public researcher commentary or social media discussion has been identified beyond standard vendor advisory channels (SUSE Advisory, Red Hat Bugzilla).

Additional resources


SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-64557NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-rt-selftests-internal
NoNoJul 29, 2026
CVE-2026-64556NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-64k-devel
NoNoJul 29, 2026
CVE-2026-64555NONEN/A
  • Linux Kernel logoLinux Kernel
  • linux-azure-fde-6.14
NoNoJul 27, 2026
CVE-2026-64554NONEN/A
  • Linux Kernel logoLinux Kernel
  • linux-gcp-6.14
NoYesJul 27, 2026
CVE-2026-64553NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-rt-64k-debug-modules-internal
NoYesJul 27, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management