{"id":"CVE-2026-93793","summary":"wifi: iwlwifi: mvm: validate TX_CMD response layout","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: iwlwifi: mvm: validate TX_CMD response layout\n\nTX_CMD parsing uses frame_count to walk status entries and then\nread the trailing SCD SSN. Make the minimum-length check follow\nthat exact runtime layout calculation before parsing the payload.\n\nFor new TX API, reject TX_CMD responses with frame_count != 1 and\nwarn/return in the aggregation handler to document that aggregated\naccounting is expected via BA notifications.","modified":"2026-09-26T03:48:39.539851177Z","published":"2026-09-24T16:02:26.708Z","database_specific":{"cna_assigner":"Linux","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/93xxx/CVE-2026-93793.json"},"references":[{"type":"WEB","url":"https://git.kernel.org/stable/c/4d942dfc13aec393e003ab28ff58db744c26e6eb"},{"type":"WEB","url":"https://git.kernel.org/stable/c/8d70881707b47353359df57df12f6de67fdacdd2"},{"type":"WEB","url":"https://git.kernel.org/stable/c/fc14f5fe8a4374ed1088cfbddc1dae4d16c9935b"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/93xxx/CVE-2026-93793.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-93793"},{"type":"PACKAGE","url":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"8ca151b568b67a7b72dcfc6ee6ea7c107ddd795c"},{"fixed":"fc14f5fe8a4374ed1088cfbddc1dae4d16c9935b"},{"fixed":"4d942dfc13aec393e003ab28ff58db744c26e6eb"},{"fixed":"8d70881707b47353359df57df12f6de67fdacdd2"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-93793.json"}},{"package":{"name":"Kernel","ecosystem":"Linux"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"3.9.0"},{"fixed":"6.12.111"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.13.0"},{"fixed":"6.18.53"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-93793.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}