{"id":"CVE-2026-93793","published":"2026-09-24T17:17:12.050","lastModified":"2026-09-25T13:17:19.883","description":"In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: iwlwifi: mvm: validate TX_CMD response layout\n\nTX_CMD parsing uses frame_count to walk status entries and then\nread the trailing SCD SSN. Make the minimum-length check follow\nthat exact runtime layout calculation before parsing the payload.\n\nFor new TX API, reject TX_CMD responses with frame_count != 1 and\nwarn/return in the aggregation handler to document that aggregated\naccounting is expected via BA notifications.","cvssScore":8.8,"cvssSeverity":"HIGH","cvssVector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cwes":[],"vendors":[],"products":[],"references":[{"url":"https://git.kernel.org/stable/c/4d942dfc13aec393e003ab28ff58db744c26e6eb","tags":[]},{"url":"https://git.kernel.org/stable/c/8d70881707b47353359df57df12f6de67fdacdd2","tags":[]},{"url":"https://git.kernel.org/stable/c/fc14f5fe8a4374ed1088cfbddc1dae4d16c9935b","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":{"summary":"This vulnerability in the iwlwifi driver for the Linux kernel allows an attacker to exploit misinterpreted TX_CMD responses, leading to potential system instability or security issues.","exploitability":"Exploitation requires specific conditions, such as the presence of certain TX_CMD responses, making it moderately difficult. Precondition is the availability of the affected TX API.","blast_radius":"If exploited, the impact could range from system crashes to more severe security breaches, depending on the system's configuration and the attacker's capabilities.","remediation":"Upgrade to the Linux kernel version 6.1.18 or later.","detection":"No reliable host or network indicator is derivable from the published description.","tags":["kernel","wireless","tx-cmd"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-29T09:00:59.699Z"}}