CVE-2026-93784
Błąd w walidacji bufora IE w jądrze Linux prowadzi do odczytu poza granicami pamięci.
In the Linux kernel, the following vulnerability has been resolved: wifi: cfg80211: validate IEs in cfg80211_wext_siwgenie() The KASAN allocation trace shows that a malformed IE buffer is stored via SIOCSIWGENIE (cfg80211_wext_siwgenie()) without any validation. The crash trace shows that a subsequent SIOCSIWESSID triggers a connection attempt which calls cfg80211_sme_get_conn_ies() to process the stored IE buffer, causing: - An out-of-bounds read in skip_ie() which reads ies[pos+1] (the length byte) past the end of the 1-byte buffer. - An integer underflow in the memcpy size argument when offs returned by ieee80211_ie_split() exceeds ies_len, causing unsigned subtraction to wrap to SIZE_MAX and triggering a fortify panic. Fix this by validating the IE buffer in cfg80211_wext_siwgenie() before storing it. [drop unnecessary ie_len check, update commit message]
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 0.0 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 0.2% |
| Opublikowano (NVD) | 2026-09-24 17:17:11 UTC |
| Ostatnia modyfikacja (NVD) | 2026-10-03 11:17:47 UTC |
- https://git.kernel.org/stable/c/01cc395cecfaa73134d39fb9a401d9605d8bb2c5 (416baaa9-dc9f-4396-8d5f-8c081fb06d67)
- https://git.kernel.org/stable/c/269498ce6c1e2132b072aa0c8660404926008f03 (416baaa9-dc9f-4396-8d5f-8c081fb06d67)
- https://git.kernel.org/stable/c/685082f4be77f4657b498ebbe9f942ef65c492cf (416baaa9-dc9f-4396-8d5f-8c081fb06d67)
- https://git.kernel.org/stable/c/8b921a8993469a3482e0c67b5ce5cb6ce93f5f61 (416baaa9-dc9f-4396-8d5f-8c081fb06d67)
- https://git.kernel.org/stable/c/a2f5286ca4f304d3fd469f01b96b518608912a5c (416baaa9-dc9f-4396-8d5f-8c081fb06d67)
- https://git.kernel.org/stable/c/c970879e03b23a27df42caf7ba506485a165fb96 (416baaa9-dc9f-4396-8d5f-8c081fb06d67)
- https://git.kernel.org/stable/c/d01f1600e8b075aa17adb751ac9881bb6ee40dcc (416baaa9-dc9f-4396-8d5f-8c081fb06d67)