OCTOBER 9, 2026
Live Feed
Back to database
Case File

CVE-2026-93799

HIGH · CVSS 8.8 EPSS 0.24%

Source: NVD + CISA KEV + EPSS · Published 2026-09-24 · Last synced 2026-10-09

CyberRota Analysis

AI-Generated

The vulnerability affects the Linux kernel's iwlwifi driver, specifically in the handling of the BA_WINDOW_STATUS_NOTIFICATION_ID, which improperly extracts a 5-bit sta_id for indexing without sufficient bounds checking. This flaw could lead to out-of-bounds memory access, potentially allowing attackers to execute arbitrary code or cause a denial of service. Linux system administrators and developers utilizing the iwlwifi driver should prioritize addressing this vulnerability to mitigate potential exploitation risks.

CVE
CVE-2026-93799
Severity
HIGH
CVSS
8.8
EPSS
0.24%
Linux

Original NVD Description

In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: mvm: validate sta_id in BA window status notif BA_WINDOW_STATUS_NOTIFICATION_ID extracts a 5-bit sta_id from the firmware notification and uses it to index fw_id_to_mac_id[] without bounds checking. Validate sta_id before array access to prevent out-of-bounds indexing.