{
  "affected": [
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:12",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:13",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:14",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "details": "In the Linux kernel, the following vulnerability has been resolved:  wifi: mwifiex: Detach sync cmd buffer on interrupted wait  mwifiex synchronous commands keep the caller-provided data buffer in cmd_node-\u003edata_buf. Several callers pass stack-allocated objects there.  If wait_event_interruptible_timeout() is interrupted, the caller can return and release that stack object while the firmware command is still the current command. A late firmware response then reaches the normal response handler, which can copy data through cmd_node-\u003edata_buf into the stale stack address.  This fixes a stack corruption observed during repeated association and disassociation cycles. The panic trace showed the command wait being interrupted immediately before a bad pointer dereference:    cmd_wait_q terminated: -512   Unable to handle kernel paging request at virtual address 002c583837384662   Kernel panic - not syncing: stack-protector: Kernel stack is corrupted   ...   Tainted: [M]=MACHINE_CHECK  The fault address decodes as little-endian ASCII:    0x002c583837384662 -\u003e \"bF878X,\\0\"  which is a fragment of the VERSION_EXT firmware string exposed as debugfs \"verext\":    w8997o-V4, RF878X, FP92, 16.92.21.p153.7  The same runs also showed corrupted control data containing:    0x2400372e333531 -\u003e \"153.7\\0$\"  which is the tail of the same VERSION_EXT string. This points at a late VERSION_EXT response writing through a stale stack-backed data_buf after the interrupted wait returned.  After cancelling pending commands on an interrupted or timed-out wait, detach the caller-owned data buffer from the still-current command. This preserves the existing command cancellation behaviour while preventing a late response from writing through a pointer whose lifetime ended with the waiting caller.  Tested on an i.MX8MP board using an 88W8997.",
  "id": "DEBIAN-CVE-2026-80944",
  "modified": "2026-09-15T08:47:37.669651653Z",
  "published": "2026-09-11T20:18:59.923Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://security-tracker.debian.org/tracker/CVE-2026-80944"
    }
  ],
  "severity": [
    {
      "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "type": "CVSS_V3"
    }
  ],
  "upstream": [
    "CVE-2026-80944"
  ]
}