OCTOBER 9, 2026
Live Feed
Back to database
Case File

CVE-2026-93790

HIGH · CVSS 8.8 EPSS 0.24%

Source: NVD + CISA KEV + EPSS · Published 2026-09-24 · Last synced 2026-10-09

CyberRota Analysis

AI-Generated

The vulnerability affects the Linux kernel's iwlwifi driver, where an out-of-bounds access to the `tid_data` array occurs due to incorrect indexing by a loop counter instead of the actual TID value. Although the impact is currently limited since the multi-TID block acknowledgment feature is rarely used, it poses a potential risk for future exploitation if this feature becomes more prevalent. Linux system administrators and developers utilizing the iwlwifi driver should prioritize applying the fix to mitigate any unforeseen risks.

CVE
CVE-2026-93790
Severity
HIGH
CVSS
8.8
EPSS
0.24%
Linux

Original NVD Description

In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: mvm: fix out-of-bounds tid_data access in BA notif mvmsta->tid_data was indexed by the TFD loop counter 'i' instead of the actual TID value 'tid'. This writes lq_color into a random tid_data slot unrelated to the BA entry. Since multi-TID blockack is not really in use, 'i' was always 0 and no harm was done. Add a out-of-bound check before accessing the array.