CVE-2026-93803
⚪ Do wiadomości
Błąd w libipw w jądrze Linux umożliwia odczyt nieprawidłowych danych, co może prowadzić do nieprzewidzianych zachowań.
CVSS
0.0
EPSS
0.2%
Exploit
none
Vendor
Opis źródłowy (NVD)
In the Linux kernel, the following vulnerability has been resolved: wifi: libipw: fix key index receive bound checks libipw_rx() reads skb->data[hdrlen + 3] to extract the WEP key index in both the software-decrypt key selection path and the hardware-decrypted IV/ICV strip path. In both places the existing guard only checks skb->len >= hdrlen + 3, which proves bytes up to hdrlen + 2 but not the byte at hdrlen + 3. Require hdrlen + 4 bytes before reading that item in both paths. This is a local source-boundary check only; it does not change the key index semantics.
brak
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 0.0 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 0.2% |
| Opublikowano (NVD) | 2026-09-24 17:17:13 UTC |
| Ostatnia modyfikacja (NVD) | 2026-10-03 11:17:50 UTC |
Referencje
- https://git.kernel.org/stable/c/062840bdc9ee06169b3c371bf66711f1d7ec0bf4 (416baaa9-dc9f-4396-8d5f-8c081fb06d67)
- https://git.kernel.org/stable/c/09d4a1bc3a08bb0e19bdf250b9f575cfef0bae82 (416baaa9-dc9f-4396-8d5f-8c081fb06d67)
- https://git.kernel.org/stable/c/0b61c465ea62063593bc9ac186871b69e58ae991 (416baaa9-dc9f-4396-8d5f-8c081fb06d67)
- https://git.kernel.org/stable/c/2836a870f612a8a6d9e390d00fa2cf6c90aa5808 (416baaa9-dc9f-4396-8d5f-8c081fb06d67)
- https://git.kernel.org/stable/c/74ed3669f26803b1761c1f55403062bea44c3466 (416baaa9-dc9f-4396-8d5f-8c081fb06d67)
- https://git.kernel.org/stable/c/bb18262c19feb690ddde58c70e3ad04bc6fe566e (416baaa9-dc9f-4396-8d5f-8c081fb06d67)
- https://git.kernel.org/stable/c/c54b643e9a0936d038921c547736574fd7382cea (416baaa9-dc9f-4396-8d5f-8c081fb06d67)