CVE-2026-93799
🟡 Monitoruj
Brak walidacji sta_id w iwlwifi pozwala na dostęp do pamięci poza przydzielonym zakresem.
CVSS
8.8
EPSS
0.2%
Exploit
none
Vendor
Opis źródłowy (NVD)
In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: mvm: validate sta_id in BA window status notif BA_WINDOW_STATUS_NOTIFICATION_ID extracts a 5-bit sta_id from the firmware notification and uses it to index fw_id_to_mac_id[] without bounds checking. Validate sta_id before array access to prevent out-of-bounds indexing.
brak
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 8.8 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 0.2% |
| Opublikowano (NVD) | 2026-09-24 17:17:12 UTC |
| Ostatnia modyfikacja (NVD) | 2026-10-03 11:17:49 UTC |
Referencje
- https://git.kernel.org/stable/c/6aa77efaea9efea92e3090c35ad348fd759a3cf3 (416baaa9-dc9f-4396-8d5f-8c081fb06d67)
- https://git.kernel.org/stable/c/bb08fbbbd5568d33069485ecb0a1657f115a4e9f (416baaa9-dc9f-4396-8d5f-8c081fb06d67)
- https://git.kernel.org/stable/c/e35ae757c6462bfd3437bf58121bb721fe1f790c (416baaa9-dc9f-4396-8d5f-8c081fb06d67)
- https://git.kernel.org/stable/c/f9938eb95e2ddab4a58d3946a320abcbd60b56a4 (416baaa9-dc9f-4396-8d5f-8c081fb06d67)