OCTOBER 9, 2026
Live Feed
Back to database
Case File

CVE-2026-93793

HIGH · CVSS 8.8 EPSS 0.24%

Source: NVD + CISA KEV + EPSS · Published 2026-09-24 · Last synced 2026-10-09

CyberRota Analysis

AI-Generated

The vulnerability affects the Linux kernel's iwlwifi driver, specifically in the handling of TX_CMD responses, which could lead to improper parsing of status entries and potential exploitation through malformed packets. This flaw may allow attackers to disrupt wireless communication or manipulate data transmission. Organizations using Linux systems with the iwlwifi driver should prioritize addressing this vulnerability to ensure the integrity and reliability of their wireless networks.

CVE
CVE-2026-93793
Severity
HIGH
CVSS
8.8
EPSS
0.24%
Linux

Original NVD Description

In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: mvm: validate TX_CMD response layout TX_CMD parsing uses frame_count to walk status entries and then read the trailing SCD SSN. Make the minimum-length check follow that exact runtime layout calculation before parsing the payload. For new TX API, reject TX_CMD responses with frame_count != 1 and warn/return in the aggregation handler to document that aggregated accounting is expected via BA notifications.