PatchSiren cyber security CVE debrief
CVE-2026-80635 Linux CVE debrief
The Linux kernel's wifi wcn36xx driver has an out-of-bounds read vulnerability due to insufficient validation of firmware response length, tracked as CVE-2026-80635. This HIGH-severity vulnerability, with a CVSS score of 8.8, could potentially corrupt BA session state. The vulnerability is resolved by adding validation that the response includes the candidate data. Affected product deployments should be reviewed for wifi wcn36xx usage, and patches should be applied as soon as possible to mitigate potential risks. The CVE record was published on 2026-08-28T08:16:48.400Z and has not been modified since then. The NVD entry is currently marked as Received. Linux kernel source references detail patch commits for wifi wcn36xx firmware response validation.
- Vendor
- Linux
- Product
- Unknown
- CVSS
- HIGH 8.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-28
- Original CVE updated
- 2026-08-29
- Advisory published
- 2026-08-28
- Advisory updated
- 2026-08-29
Who should care
Linux kernel maintainers, wifi wcn36xx users, organizations relying on Linux kernel-based systems, and security teams responsible for vulnerability management should prioritize patching for this HIGH-severity vulnerability. The vulnerability affects the Linux kernel's wifi wcn36xx driver and has a significant impact due to its potential to corrupt BA session state. Affected operators and platforms should review and apply patches as soon as possible to mitigate potential risks.
Technical summary
The Linux kernel wifi wcn36xx driver has an out-of-bounds read vulnerability due to insufficient validation of firmware response length. This vulnerability, tracked as CVE-2026-80635, has a HIGH CVSS score of 8.8 and could potentially corrupt BA session state. The vulnerability is resolved by adding validation that the response includes the candidate data. The affected product is the Linux kernel, specifically the wifi wcn36xx driver. The vulnerability does not require authentication or specific conditions to be exploited, making it a high-priority patch for Linux kernel maintainers and users of wifi wcn36xx.
Defensive priority
Linux kernel vulnerability with HIGH CVSS score of 8.8; prioritize patching for wifi wcn36xx firmware response validation.
Recommended defensive actions
- Apply patch to validate wifi wcn36xx firmware response length
- Inventory Linux kernel installations for wifi wcn36xx usage
- Monitor for suspicious wifi wcn36xx activity
- Verify Linux kernel patch deployment
- Update incident response plan to include wifi wcn36xx vulnerability
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
Evidence notes
The CVE record for CVE-2026-80635 was published on 2026-08-28T08:16:48.400Z and has not been modified since then. The NVD entry is currently marked as Received. The Linux kernel wifi wcn36xx driver has an out-of-bounds read vulnerability due to insufficient validation of firmware response length. This vulnerability has a HIGH CVSS score of 8.8. The official CVE Program record and NIST NVD detail page provide vulnerability metadata. Linux kernel source references detail patch commits for wifi wcn36xx firmware response validation. However, the current details do not provide specific information on the affected products, exploitation methods, or potential impacts beyond the Linux kernel context.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-80635 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-80635
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-80635 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-80635
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/04aba50212f9f274e1a726fb3873b5ce8da2d821
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/af8f0ea1f0a3a5fb5ed2b8fed3f1501d644597ee
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/b5e6f21923ca89d90256e7346301056f6502691e
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/c07aa0534d50361183833e3803204044cf1d0476
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/d0b57bcd0dac6e2c9a3e474ec280e7db0b3edf35
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/d0cafe6ed8d1f6d0097eda31d85f5760d4f359c2
416baaa9-dc9f-4396-8d5f-8c081fb06d67
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.