{"id":"CVE-2026-93784","published":"2026-09-24T17:17:11.017","lastModified":"2026-09-25T13:17:18.943","description":"In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: cfg80211: validate IEs in cfg80211_wext_siwgenie()\n\nThe KASAN allocation trace shows that a malformed IE buffer is\nstored via SIOCSIWGENIE (cfg80211_wext_siwgenie()) without any\nvalidation. The crash trace shows that a subsequent SIOCSIWESSID\ntriggers a connection attempt which calls cfg80211_sme_get_conn_ies()\nto process the stored IE buffer, causing:\n\n - An out-of-bounds read in skip_ie() which reads ies[pos+1]\n   (the length byte) past the end of the 1-byte buffer.\n\n - An integer underflow in the memcpy size argument when offs\n   returned by ieee80211_ie_split() exceeds ies_len, causing\n   unsigned subtraction to wrap to SIZE_MAX and triggering a\n   fortify panic.\n\nFix this by validating the IE buffer in cfg80211_wext_siwgenie()\nbefore storing it.\n\n[drop unnecessary ie_len check, update commit message]","cvssScore":null,"cvssSeverity":null,"cvssVector":null,"cwes":[],"vendors":[],"products":[],"references":[{"url":"https://git.kernel.org/stable/c/01cc395cecfaa73134d39fb9a401d9605d8bb2c5","tags":[]},{"url":"https://git.kernel.org/stable/c/a2f5286ca4f304d3fd469f01b96b518608912a5c","tags":[]},{"url":"https://git.kernel.org/stable/c/c970879e03b23a27df42caf7ba506485a165fb96","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":null}