
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-98159 is a memory validation flaw in the Linux kernel's mt76 WiFi driver (mt7921 module) that allows a local attacker to trigger out-of-bounds memory access by supplying a malformed firmware image. The vulnerability was published on September 25, 2026, and affects Linux kernel versions starting from commit 23bdc5d8cadfc941e7782d0cb8afb2d9ae73b125 (introduced in kernel 6.1) up to the respective fix commits across stable branches. Patched versions include kernel 6.12.111, 6.18.53, 7.2.7, and 7.3-rc1. No CVSS score has been formally assigned; Feedly estimates the severity as Medium (Github Advisory, Feedly).
The root cause is improper input validation (CWE not formally assigned) in the CLC (Channel List Configuration) firmware record loader within the mt7921 driver. The driver unconditionally trusts the region count and individual record lengths embedded in the firmware image without bounds checking, enabling three distinct unsafe conditions: the region table pointer can be made to precede the firmware buffer (out-of-bounds read), the record processing loop can fail to advance (infinite loop / denial of service), or the phy->clc array can be indexed past its end (out-of-bounds access). Exploitation requires the ability to supply or modify the WiFi firmware image loaded by the driver, which is a local privilege precondition. The fix adds validation of table and record bounds before any dereference or copy operation (Github Advisory, Feedly).
A local user with the ability to supply or modify the mt7921 WiFi firmware can cause out-of-bounds kernel memory access, leading to potential disclosure of sensitive kernel memory contents (confidentiality impact) or a kernel crash resulting in denial of service (availability impact). Integrity impact is limited, as the flaw does not directly enable arbitrary kernel write primitives based on currently available information. The vulnerability is scoped to systems running the mt76/mt7921 WiFi driver with the affected kernel versions (Feedly).
There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation as of the disclosure date. The attack type is classified as local code execution, requiring the attacker to have local access and the ability to supply a malformed firmware image. The EPSS score is 0.0, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. No threat actor attribution has been reported (Feedly, Github Advisory).
Update the Linux kernel to a patched version: 6.12.111, 6.18.53, 7.2.7, or 7.3-rc1 and later. The specific fix commits are 602a950134ee, 3896be051e92, 3c505e2af16a, and 9417c5818a01 on the stable kernel trees. As a compensating control, restrict firmware loading capabilities to privileged users only and implement secure boot with firmware verification to prevent unauthorized firmware modifications. Systems not using MediaTek mt7921 WiFi hardware are not affected (Github Advisory, Feedly).
Fix availability across major Linux distributions and their releases.
bionic (esm-infra)
linux
bionic (fips-updates)
linux-fips
bionic (fips)
linux-fips
devel
linux
focal (esm-infra)
linux
focal (fips-updates)
linux-fips
focal (fips)
linux-fips
jammy
linux
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."