{"id":"CVE-2026-93799","published":"2026-09-24T17:17:12.720","lastModified":"2026-09-25T13:17:20.663","description":"In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: iwlwifi: mvm: validate sta_id in BA window status notif\n\nBA_WINDOW_STATUS_NOTIFICATION_ID extracts a 5-bit sta_id from the\nfirmware notification and uses it to index fw_id_to_mac_id[] without\nbounds checking. Validate sta_id before array access to prevent\nout-of-bounds indexing.","cvssScore":8.8,"cvssSeverity":"HIGH","cvssVector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cwes":[],"vendors":[],"products":[],"references":[{"url":"https://git.kernel.org/stable/c/6aa77efaea9efea92e3090c35ad348fd759a3cf3","tags":[]},{"url":"https://git.kernel.org/stable/c/bb08fbbbd5568d33069485ecb0a1657f115a4e9f","tags":[]},{"url":"https://git.kernel.org/stable/c/e35ae757c6462bfd3437bf58121bb721fe1f790c","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":{"summary":"This vulnerability allows out-of-bounds indexing in the iwlwifi driver, which could lead to potential kernel crashes or privilege escalation if exploited.","exploitability":"Exploitation requires access to the wireless network and knowledge of the specific firmware version. The vulnerability is not easily exploitable without these preconditions.","blast_radius":"If exploited, the impact could be severe, potentially leading to a denial of service or privilege escalation on the affected system.","remediation":"Upgrade to the fixed version 6200-31 or later.","detection":"No reliable host or network indicator is derivable from the published description.","tags":["kernel","wireless","privilege-escalation"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-29T09:01:10.279Z"}}