CVE-2026-74324
In the Linux kernel, the following vulnerability has been resolved:
wifi: mt76: mt7925: validate skb length in testmode query
In mt7925_tm_query(), the response skb from mt76_mcu_send_and_get_msg() is used in a memcpy without validating its length:
where MT7925_EVT_RSP_LEN is 512. If the firmware returns a response shorter than 520 bytes (8 + 512), this reads beyond the skb data buffer. The over-read data is then returned to userspace via nla_put() in mt7925_testmode_dump().
Add a length check before the memcpy to ensure the skb contains sufficient data.
Detalles técnicos trazas, registros y código del informe original
memcpy(evt_resp, skb->data + 8, MT7925_EVT_RSP_LEN);
CVSS
NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.21%
- Percentil entre todas las CVEs puntuadas: 10
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-74324",
"cveTags": [],
"metrics": {},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "c948b5da6bbec742b433138e3e3f9537a85af2e5",
"lessThan": "c386e90a7ce8ddec9f038e9437661a2821b0ce89",
"versionType": "git"
},
{
"status": "affected",
"version": "c948b5da6bbec742b433138e3e3f9537a85af2e5",
"lessThan": "e8b214b6d6e1902025452db0a0af73dc9693e4ba",
"versionType": "git"
},
{
"status": "affected",
"version": "c948b5da6bbec742b433138e3e3f9537a85af2e5",
"lessThan": "c7369a00860a0704461d440e7c3bf9b49bfdbaee",
"versionType": "git"
}
],
"programFiles": [
"drivers/net/wireless/mediatek/mt76/mt7925/testmode.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "6.7"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "6.7",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "6.18.40",
"versionType": "semver",
"lessThanOrEqual": "6.18.*"
},
{
"status": "unaffected",
"version": "7.1.5",
"versionType": "semver",
"lessThanOrEqual": "7.1.*"
},
{
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"drivers/net/wireless/mediatek/mt76/mt7925/testmode.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-08-15T06:22:33.000",
"references": [
{
"url": "https://git.kernel.org/stable/c/c386e90a7ce8ddec9f038e9437661a2821b0ce89",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/c7369a00860a0704461d440e7c3bf9b49bfdbaee",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/e8b214b6d6e1902025452db0a0af73dc9693e4ba",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: mt76: mt7925: validate skb length in testmode query\n\nIn mt7925_tm_query(), the response skb from mt76_mcu_send_and_get_msg()\nis used in a memcpy without validating its length:\n\n memcpy(evt_resp, skb->data + 8, MT7925_EVT_RSP_LEN);\n\nwhere MT7925_EVT_RSP_LEN is 512. If the firmware returns a response\nshorter than 520 bytes (8 + 512), this reads beyond the skb data\nbuffer. The over-read data is then returned to userspace via nla_put()\nin mt7925_testmode_dump().\n\nAdd a length check before the memcpy to ensure the skb contains\nsufficient data."
}
],
"lastModified": "2026-08-17T06:19:26.840",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}