← Back to search

CVE-2026-93799

8.8 HIGH

Published 2026-09-24 · Updated 2026-09-25

AI risk analysis

Summary
This vulnerability allows out-of-bounds indexing in the iwlwifi driver, which could lead to potential kernel crashes or privilege escalation if exploited.
Exploitability
Exploitation requires access to the wireless network and knowledge of the specific firmware version. The vulnerability is not easily exploitable without these preconditions.
Blast radius
If exploited, the impact could be severe, potentially leading to a denial of service or privilege escalation on the affected system.
Detection
No reliable host or network indicator is derivable from the published description.
Prioritized remediation
Upgrade to the fixed version 6200-31 or later.
kernelwirelessprivilege-escalation

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: mvm: validate sta_id in BA window status notif BA_WINDOW_STATUS_NOTIFICATION_ID extracts a 5-bit sta_id from the firmware notification and uses it to index fw_id_to_mac_id[] without bounds checking. Validate sta_id before array access to prevent out-of-bounds indexing.

CVSS vector

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.