8.8

CVE-2026-93793

wifi: iwlwifi: mvm: validate TX_CMD response layout

In the Linux kernel, the following vulnerability has been resolved:

wifi: iwlwifi: mvm: validate TX_CMD response layout

TX_CMD parsing uses frame_count to walk status entries and then
read the trailing SCD SSN. Make the minimum-length check follow
that exact runtime layout calculation before parsing the payload.

For new TX API, reject TX_CMD responses with frame_count != 1 and
warn/return in the aggregation handler to document that aggregated
accounting is expected via BA notifications.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 8ca151b568b67a7b72dcfc6ee6ea7c107ddd795c
Version < fc14f5fe8a4374ed1088cfbddc1dae4d16c9935b
Status affected
Version 8ca151b568b67a7b72dcfc6ee6ea7c107ddd795c
Version < 4d942dfc13aec393e003ab28ff58db744c26e6eb
Status affected
Version 8ca151b568b67a7b72dcfc6ee6ea7c107ddd795c
Version < 8d70881707b47353359df57df12f6de67fdacdd2
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 3.9
Status affected
Version 0
Version < 3.9
Status unaffected
Version <= 6.12.*
Version 6.12.111
Status unaffected
Version <= 6.18.*
Version 6.18.53
Status unaffected
Version <= *
Version 7.2
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.24% 0.133
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 8.8 2.8 5.9
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/fc14f5fe8a4374ed1088cfbddc1dae4d16c9935b
https://git.kernel.org/stable/c/4d942dfc13aec393e003ab28ff58db744c26e6eb
https://git.kernel.org/stable/c/8d70881707b47353359df57df12f6de67fdacdd2