PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-80635 Linux CVE debrief

The Linux kernel's wifi wcn36xx driver has an out-of-bounds read vulnerability due to insufficient validation of firmware response length, tracked as CVE-2026-80635. This HIGH-severity vulnerability, with a CVSS score of 8.8, could potentially corrupt BA session state. The vulnerability is resolved by adding validation that the response includes the candidate data. Affected product deployments should be reviewed for wifi wcn36xx usage, and patches should be applied as soon as possible to mitigate potential risks. The CVE record was published on 2026-08-28T08:16:48.400Z and has not been modified since then. The NVD entry is currently marked as Received. Linux kernel source references detail patch commits for wifi wcn36xx firmware response validation.

Vendor
Linux
Product
Unknown
CVSS
HIGH 8.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-28
Original CVE updated
2026-08-29
Advisory published
2026-08-28
Advisory updated
2026-08-29

Who should care

Linux kernel maintainers, wifi wcn36xx users, organizations relying on Linux kernel-based systems, and security teams responsible for vulnerability management should prioritize patching for this HIGH-severity vulnerability. The vulnerability affects the Linux kernel's wifi wcn36xx driver and has a significant impact due to its potential to corrupt BA session state. Affected operators and platforms should review and apply patches as soon as possible to mitigate potential risks.

Technical summary

The Linux kernel wifi wcn36xx driver has an out-of-bounds read vulnerability due to insufficient validation of firmware response length. This vulnerability, tracked as CVE-2026-80635, has a HIGH CVSS score of 8.8 and could potentially corrupt BA session state. The vulnerability is resolved by adding validation that the response includes the candidate data. The affected product is the Linux kernel, specifically the wifi wcn36xx driver. The vulnerability does not require authentication or specific conditions to be exploited, making it a high-priority patch for Linux kernel maintainers and users of wifi wcn36xx.

Defensive priority

Linux kernel vulnerability with HIGH CVSS score of 8.8; prioritize patching for wifi wcn36xx firmware response validation.

Recommended defensive actions

  • Apply patch to validate wifi wcn36xx firmware response length
  • Inventory Linux kernel installations for wifi wcn36xx usage
  • Monitor for suspicious wifi wcn36xx activity
  • Verify Linux kernel patch deployment
  • Update incident response plan to include wifi wcn36xx vulnerability
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented

Evidence notes

The CVE record for CVE-2026-80635 was published on 2026-08-28T08:16:48.400Z and has not been modified since then. The NVD entry is currently marked as Received. The Linux kernel wifi wcn36xx driver has an out-of-bounds read vulnerability due to insufficient validation of firmware response length. This vulnerability has a HIGH CVSS score of 8.8. The official CVE Program record and NIST NVD detail page provide vulnerability metadata. Linux kernel source references detail patch commits for wifi wcn36xx firmware response validation. However, the current details do not provide specific information on the affected products, exploitation methods, or potential impacts beyond the Linux kernel context.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-80635 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-80635

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-80635 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-80635

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/04aba50212f9f274e1a726fb3873b5ce8da2d821

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/af8f0ea1f0a3a5fb5ed2b8fed3f1501d644597ee

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/b5e6f21923ca89d90256e7346301056f6502691e

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/c07aa0534d50361183833e3803204044cf1d0476

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/d0b57bcd0dac6e2c9a3e474ec280e7db0b3edf35

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/d0cafe6ed8d1f6d0097eda31d85f5760d4f359c2

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.