{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-93784","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-18T17:59:28.788Z","datePublished":"2026-09-24T16:02:18.067Z","dateUpdated":"2026-10-03T10:57:19.164Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-10-03T10:57:19.164Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: cfg80211: validate IEs in cfg80211_wext_siwgenie()\n\nThe KASAN allocation trace shows that a malformed IE buffer is\nstored via SIOCSIWGENIE (cfg80211_wext_siwgenie()) without any\nvalidation. The crash trace shows that a subsequent SIOCSIWESSID\ntriggers a connection attempt which calls cfg80211_sme_get_conn_ies()\nto process the stored IE buffer, causing:\n\n - An out-of-bounds read in skip_ie() which reads ies[pos+1]\n   (the length byte) past the end of the 1-byte buffer.\n\n - An integer underflow in the memcpy size argument when offs\n   returned by ieee80211_ie_split() exceeds ies_len, causing\n   unsigned subtraction to wrap to SIZE_MAX and triggering a\n   fortify panic.\n\nFix this by validating the IE buffer in cfg80211_wext_siwgenie()\nbefore storing it.\n\n[drop unnecessary ie_len check, update commit message]"}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["net/wireless/wext-sme.c"],"versions":[{"version":"f21293549f60f88c74fcb9944737f11048896dc4","lessThan":"269498ce6c1e2132b072aa0c8660404926008f03","status":"affected","versionType":"git"},{"version":"f21293549f60f88c74fcb9944737f11048896dc4","lessThan":"685082f4be77f4657b498ebbe9f942ef65c492cf","status":"affected","versionType":"git"},{"version":"f21293549f60f88c74fcb9944737f11048896dc4","lessThan":"8b921a8993469a3482e0c67b5ce5cb6ce93f5f61","status":"affected","versionType":"git"},{"version":"f21293549f60f88c74fcb9944737f11048896dc4","lessThan":"d01f1600e8b075aa17adb751ac9881bb6ee40dcc","status":"affected","versionType":"git"},{"version":"f21293549f60f88c74fcb9944737f11048896dc4","lessThan":"c970879e03b23a27df42caf7ba506485a165fb96","status":"affected","versionType":"git"},{"version":"f21293549f60f88c74fcb9944737f11048896dc4","lessThan":"01cc395cecfaa73134d39fb9a401d9605d8bb2c5","status":"affected","versionType":"git"},{"version":"f21293549f60f88c74fcb9944737f11048896dc4","lessThan":"a2f5286ca4f304d3fd469f01b96b518608912a5c","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["net/wireless/wext-sme.c"],"versions":[{"version":"2.6.32","status":"affected"},{"version":"0","lessThan":"2.6.32","status":"unaffected","versionType":"semver"},{"version":"5.10.271","lessThanOrEqual":"5.10.*","status":"unaffected","versionType":"semver"},{"version":"5.15.222","lessThanOrEqual":"5.15.*","status":"unaffected","versionType":"semver"},{"version":"6.1.189","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.158","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.111","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.53","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.32","versionEndExcluding":"5.10.271"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.32","versionEndExcluding":"5.15.222"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.32","versionEndExcluding":"6.1.189"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.32","versionEndExcluding":"6.6.158"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.32","versionEndExcluding":"6.12.111"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.32","versionEndExcluding":"6.18.53"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.32","versionEndExcluding":"7.2"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/269498ce6c1e2132b072aa0c8660404926008f03"},{"url":"https://git.kernel.org/stable/c/685082f4be77f4657b498ebbe9f942ef65c492cf"},{"url":"https://git.kernel.org/stable/c/8b921a8993469a3482e0c67b5ce5cb6ce93f5f61"},{"url":"https://git.kernel.org/stable/c/d01f1600e8b075aa17adb751ac9881bb6ee40dcc"},{"url":"https://git.kernel.org/stable/c/c970879e03b23a27df42caf7ba506485a165fb96"},{"url":"https://git.kernel.org/stable/c/01cc395cecfaa73134d39fb9a401d9605d8bb2c5"},{"url":"https://git.kernel.org/stable/c/a2f5286ca4f304d3fd469f01b96b518608912a5c"}],"title":"wifi: cfg80211: validate IEs in cfg80211_wext_siwgenie()","x_generator":{"engine":"bippy-1.2.0"}}}}