{"id":"CVE-2026-93790","published":"2026-09-24T17:17:11.710","lastModified":"2026-09-25T13:17:19.583","description":"In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: iwlwifi: mvm: fix out-of-bounds tid_data access in BA notif\n\nmvmsta->tid_data was indexed by the TFD loop counter 'i' instead of\nthe actual TID value 'tid'. This writes lq_color into a random tid_data\nslot unrelated to the BA entry.\nSince multi-TID blockack is not really in use, 'i' was always 0 and no\nharm was done.\nAdd a out-of-bound check before accessing the array.","cvssScore":8.8,"cvssSeverity":"HIGH","cvssVector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cwes":[],"vendors":[],"products":[],"references":[{"url":"https://git.kernel.org/stable/c/94d3982806c7f194b23484befde12934dda23064","tags":[]},{"url":"https://git.kernel.org/stable/c/c48b741277b01b2c3b4ecccedc72fc575b71dc04","tags":[]},{"url":"https://git.kernel.org/stable/c/e8ac5e91b1296f65c3d119fac3fa917ff458f811","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":{"summary":"The vulnerability allows out-of-bounds access to tid_data in the iwlwifi driver, potentially leading to data corruption or exploitation.","exploitability":"Exploitation is moderately difficult as it requires precise control over the TFD loop counter 'i' and the TID value 'tid'.","blast_radius":"If exploited, the impact could be high, potentially leading to system instability or privilege escalation.","remediation":"Upgrade to the fixed version 6.3.191 or later.","detection":"No reliable host or network indicator is derivable from the published description.","tags":["kernel","wifi","out-of-bounds","data-corruption"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-29T09:00:48.691Z"}}