{"id":"CVE-2026-93806","published":"2026-09-24T17:17:13.570","lastModified":"2026-09-25T13:17:21.450","description":"In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: cfg80211: validate assoc response length before status and IE access\n\ncfg80211_rx_assoc_resp() initialises the status and response-IE fields\nof cfg80211_connect_resp_params from the management frame before\nproving that the frame is long enough for those offsets. S1G and\nregular association responses also have different IE offsets, but the\nS1G path only patched resp_ie after the unsafe initialiser had already\nrun.\n\nDefer resp_ie, resp_ie_len, and status to after the link-iteration\nloop. Use a bool to remember whether the frame is S1G, then validate\nthe appropriate minimum length and set all three fields in a single\nif/else block. Funnel short-frame and SME-reject cleanup through a\nshared free_bss label for the abandon paths.","cvssScore":8.8,"cvssSeverity":"HIGH","cvssVector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cwes":[],"vendors":[],"products":[],"references":[{"url":"https://git.kernel.org/stable/c/78ac450ad4624d6b2999cb4eeb28916767f81247","tags":[]},{"url":"https://git.kernel.org/stable/c/a57310600c1e2b9ada0f37c96e8f48aef47d3093","tags":[]},{"url":"https://git.kernel.org/stable/c/b760113aeca2e9362d56bf9e9263373ffe6c8eb3","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":{"summary":"This vulnerability allows an attacker to exploit a flaw in the Linux kernel's cfg80211 module, potentially leading to denial of service or other attacks by manipulating association responses.","exploitability":"Exploitation requires control over a Wi-Fi association response, which is relatively difficult and typically requires an attacker to be within range of the target network.","blast_radius":"If exploited, the impact could be significant, potentially leading to service disruption or other attacks on the affected system.","remediation":"Upgrade to the specific version 5.19.1 or later, as published in the advisory.","detection":"No reliable host or network indicator is derivable from the published description.","tags":["wifi","kernel","association","dos"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-29T09:01:20.998Z"}}