OCTOBER 9, 2026
Live Feed
Back to database
Case File

CVE-2026-93796

HIGH · CVSS 7 EPSS 0.12%

Source: NVD + CISA KEV + EPSS · Published 2026-09-24 · Last synced 2026-10-09

CyberRota Analysis

AI-Generated

The vulnerability affects the iwlwifi driver in the Linux kernel, where improper handling of RX pointers after memory deallocation can lead to the use of stale data during subsequent operations. This flaw could potentially result in system instability or crashes if the affected components are accessed again after being freed. Organizations utilizing Linux systems with the iwlwifi driver should prioritize addressing this issue to ensure the stability and security of their network interfaces.

CVE
CVE-2026-93796
Severity
HIGH
CVSS
7
EPSS
0.12%
Linux

Original NVD Description

In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: pcie: null RX pointers after free When iwl_pcie_tx_init() fails after RX init, nic init unwinds via iwl_pcie_rx_free(). The freed RX members stayed non-NULL on the live transport object, so later teardown or retry could touch stale RX state. Set rx_pool, global_table, rxq, and alloc_page to NULL after free to make repeated cleanup and retry paths safe.