{
  "affected": [
    {
      "ranges": [
        {
          "events": [
            {
              "introduced": "c34dbc5900b0158edaab51c481510d66679d8f72"
            },
            {
              "fixed": "ff9748200698e9641f41ba922ffef728167807c2"
            },
            {
              "fixed": "7495adaa0e45e180f4b6b7436675c6266edff1ff"
            }
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "type": "GIT"
        }
      ]
    },
    {
      "package": {
        "ecosystem": "Linux",
        "name": "Kernel"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "7.0.0"
            },
            {
              "fixed": "7.1.5"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "database_specific": {
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/80xxx/CVE-2026-80641.json"
  },
  "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: wlcore: enable the right set of ciphers\n\nThe firmware version number check for IGTK introduced in\ncommit c34dbc5900b0 (\"wifi: wlcore: Add support for IGTK key\")\n\nlets the amount of ciphers decrease on every boot of a too old firmware and\nthat is practically happening. It also does not take into account other\nchips than the wl18xx. On some wl128x, the following can be observed\nwhen connecting via nm to a common ap:\n\n[  484.113311] wlcore: WARNING could not set keys\n[  484.117828] wlcore: ERROR Could not add or replace key\n[  484.123016] wlan0: failed to set key (5, ff:ff:ff:ff:ff:ff) to hardware (-5)\n[  484.123046] wlcore: Hardware recovery in progress. FW ver: Rev 7.3.10.0.142\n[  484.139923] wlcore: pc: 0x0, hint_sts: 0x00000048 count: 1\n[  484.145721] wlcore: down\n[  484.148986] ieee80211 phy0: Hardware restart was requested\n[  484.610473] wlcore: firmware booted (Rev 7.3.10.0.142)\n[  484.633758] wlcore: Association completed.\n[  484.690490] wlcore: ERROR command execute failure 14\n[  484.690490] ------------[ cut here ]------------\n[  484.700195] WARNING: drivers/net/wireless/ti/wlcore/main.c:872 at wl12xx_queue_recovery_work+0x64/0x74 [wlcore], CPU#0: kworker/0:0/892\n\nThis repeats endlessly.\nAlways disable IGTK on wl12xx and fix the decrementing mess.",
  "id": "CVE-2026-80641",
  "modified": "2026-08-30T03:30:32.457204424Z",
  "published": "2026-08-28T06:48:53.241Z",
  "references": [
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/7495adaa0e45e180f4b6b7436675c6266edff1ff"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/ff9748200698e9641f41ba922ffef728167807c2"
    },
    {
      "type": "ADVISORY",
      "url": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/80xxx/CVE-2026-80641.json"
    },
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-80641"
    },
    {
      "type": "PACKAGE",
      "url": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"
    }
  ],
  "schema_version": "1.9.0",
  "summary": "wifi: wlcore: enable the right set of ciphers"
}