CVE-2026-93789
⚪ Do wiadomości
Błąd w parserze iwlwifi w jądrze Linuxa umożliwia atakującemu wywołanie błędu długości.
CVSS
0.0
EPSS
0.2%
Exploit
none
Vendor
Opis źródłowy (NVD)
In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: bound aligned TLV advance in FW parser Validate ALIGN(tlv_len, 4) against remaining parser length before consuming bytes from the firmware image. This avoids length underflow on malformed TLVs.
brak
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 0.0 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 0.2% |
| Opublikowano (NVD) | 2026-09-24 17:17:11 UTC |
| Ostatnia modyfikacja (NVD) | 2026-10-03 11:17:48 UTC |
Referencje
- https://git.kernel.org/stable/c/4cfadb2e01566bc36d42922fbe18838345087050 (416baaa9-dc9f-4396-8d5f-8c081fb06d67)
- https://git.kernel.org/stable/c/528fa9eb14c209533ca26958b76da55e0ce239d8 (416baaa9-dc9f-4396-8d5f-8c081fb06d67)
- https://git.kernel.org/stable/c/61da42fdd21d98ccb8f1ec5224659f3d09202cf4 (416baaa9-dc9f-4396-8d5f-8c081fb06d67)
- https://git.kernel.org/stable/c/7aa9097623afb694bc25382a62e14d8e82bf002f (416baaa9-dc9f-4396-8d5f-8c081fb06d67)
- https://git.kernel.org/stable/c/8c332d45b736d41301b7e07f322785d821265dbc (416baaa9-dc9f-4396-8d5f-8c081fb06d67)
- https://git.kernel.org/stable/c/acad742714bdc70e7fd7f234323807c596828213 (416baaa9-dc9f-4396-8d5f-8c081fb06d67)
- https://git.kernel.org/stable/c/ce709fcab5e1d4df6d4ba980736dc5908502a40f (416baaa9-dc9f-4396-8d5f-8c081fb06d67)