CVE-2026-98159: 
Linux Kernel vulnerability analysis and mitigation

Overview

CVE-2026-98159 is a memory validation flaw in the Linux kernel's mt76 WiFi driver (mt7921 module) that allows a local attacker to trigger out-of-bounds memory access by supplying a malformed firmware image. The vulnerability was published on September 25, 2026, and affects Linux kernel versions starting from commit 23bdc5d8cadfc941e7782d0cb8afb2d9ae73b125 (introduced in kernel 6.1) up to the respective fix commits across stable branches. Patched versions include kernel 6.12.111, 6.18.53, 7.2.7, and 7.3-rc1. No CVSS score has been formally assigned; Feedly estimates the severity as Medium (Github Advisory, Feedly).

Technical details

The root cause is improper input validation (CWE not formally assigned) in the CLC (Channel List Configuration) firmware record loader within the mt7921 driver. The driver unconditionally trusts the region count and individual record lengths embedded in the firmware image without bounds checking, enabling three distinct unsafe conditions: the region table pointer can be made to precede the firmware buffer (out-of-bounds read), the record processing loop can fail to advance (infinite loop / denial of service), or the phy->clc array can be indexed past its end (out-of-bounds access). Exploitation requires the ability to supply or modify the WiFi firmware image loaded by the driver, which is a local privilege precondition. The fix adds validation of table and record bounds before any dereference or copy operation (Github Advisory, Feedly).

Impact

A local user with the ability to supply or modify the mt7921 WiFi firmware can cause out-of-bounds kernel memory access, leading to potential disclosure of sensitive kernel memory contents (confidentiality impact) or a kernel crash resulting in denial of service (availability impact). Integrity impact is limited, as the flaw does not directly enable arbitrary kernel write primitives based on currently available information. The vulnerability is scoped to systems running the mt76/mt7921 WiFi driver with the affected kernel versions (Feedly).

Exploitability

There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation as of the disclosure date. The attack type is classified as local code execution, requiring the attacker to have local access and the ability to supply a malformed firmware image. The EPSS score is 0.0, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. No threat actor attribution has been reported (Feedly, Github Advisory).

Mitigation and workarounds

Update the Linux kernel to a patched version: 6.12.111, 6.18.53, 7.2.7, or 7.3-rc1 and later. The specific fix commits are 602a950134ee, 3896be051e92, 3c505e2af16a, and 9417c5818a01 on the stable kernel trees. As a compensating control, restrict firmware loading capabilities to privileged users only and implement secure boot with firmware verification to prevent unauthorized firmware modifications. Systems not using MediaTek mt7921 WiFi hardware are not affected (Github Advisory, Feedly).

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Fixed

bookworm

linux

Affected

sid

linux: 7.2.7-1

Fixed

trixie

linux

Affected

Ubuntu

Unknown

bionic (esm-infra)

linux

Unknown

bionic (fips-updates)

linux-fips

Unknown

bionic (fips)

linux-fips

Unknown

devel

linux

Unknown

focal (esm-infra)

linux

Unknown

focal (fips-updates)

linux-fips

Unknown

focal (fips)

linux-fips

Unknown

jammy

linux

Unknown

RHEL / CentOS

Affected

OpenShift

openshift/ose-rhel-coreos-9

Affected

RHEL 8

kernel-rt.src

Affected

RHEL 9

kernel.src

Affected

RHEL 10

kernel.src

Affected

Source: This report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-100075CRITICAL9.8
  • Linux Kernel logoLinux Kernel
  • linux
NoYesSep 25, 2026
CVE-2026-98159MEDIUM6.5
  • Linux Kernel logoLinux Kernel
  • kernel-64k-debug-devel-matched
NoYesSep 25, 2026
CVE-2026-98158MEDIUM5.7
  • Linux Kernel logoLinux Kernel
  • kernel-64k-core
NoYesSep 25, 2026
CVE-2026-98161MEDIUM5.1
  • Linux Kernel logoLinux Kernel
  • kernel-rt-modules-partner
NoYesSep 25, 2026
CVE-2026-98157MEDIUM5.1
  • Linux Kernel logoLinux Kernel
  • kernel-rt-debug-core
NoYesSep 25, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management