{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-93790","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-18T17:59:28.788Z","datePublished":"2026-09-24T16:02:24.091Z","dateUpdated":"2026-10-03T10:57:25.826Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-10-03T10:57:25.826Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: iwlwifi: mvm: fix out-of-bounds tid_data access in BA notif\n\nmvmsta->tid_data was indexed by the TFD loop counter 'i' instead of\nthe actual TID value 'tid'. This writes lq_color into a random tid_data\nslot unrelated to the BA entry.\nSince multi-TID blockack is not really in use, 'i' was always 0 and no\nharm was done.\nAdd a out-of-bound check before accessing the array."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:A - iwl_mvm_rx_ba_notif is the BA_NOTIF (0xc5) handler reached from iwl_pcie_rx_handle_rb → iwl_mvm_rx_mq → iwl_mvm_rx_common. The OOB index is tfd_cnt from iwl_compressed_ba_notif, firmware’s report of a received 802.11 Block Ack, so the triggering bytes arrive over WiFi radio range, not a routable IP protocol.\nAC:L - On the new-TX-API path, iwl_mvm_rx_ba_notif writes mvmsta->tid_data[i].lq_color for i in [0, tfd_cnt) with no cap against ARRAY_SIZE(tid_data) (9). tfd_cnt is a firmware __le16 gated only by struct_size(..., tfd, tfd_cnt) versus pkt_len; a single BA_NOTIF with tfd_cnt>=10 is a deterministic sync-RX write, not a race.\nPR:N - BA_NOTIF is RX_HANDLER_SYNC with no capable() or socket-cred check. iwl_mvm_sta_from_staid_rcu only needs sta_id to name a live fw_id_to_mac_id station (associated AP or client); the RF peer needs no host uid or capability.\nUI:N - iwl_mvm_rx_ba_notif runs from NAPI when firmware posts BA_NOTIF; the victim does not mount, open a file, or otherwise act to process the compressed BA once the WiFi interface already has a station.\nS:U - tid_data sits in iwl_mvm_sta inside ieee80211_sta->drv_priv; the overflow corrupts that host kernel object and adjacent heap, and does not cross a VM, IOMMU, or sandbox authority.\nC:H - Each loop stores lq_color (TX_RES_RATE_TABLE_COL_GET of tlc_rate_info) at tid_data[i]; with tfd_cnt>=10 those 40-byte-strided writes leave the 9-element array, smash vif/ptk_pn, and continue into neighboring kernel objects, a memory-corruption disclosure primitive.\nI:H - The same store is a kernel OOB write: at i=9 the lq_color write lands on iwl_mvm_sta->vif, and larger tfd_cnt walks ptk_pn[] and off the station object, enabling pointer corruption and control-flow hijack rather than a bounded LQ-color update.\nA:H - Corrupting vif or later heap pointers in iwl_mvm_sta makes the following iwl_mvm_tx_reclaim() (which reads mvmsta->vif and tid_data[tid]) and later station use oops; an unmapped-pointer dereference in RX softirq is a host kernel crash."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/net/wireless/intel/iwlwifi/mvm/tx.c"],"versions":[{"version":"41fd2fec56db2564f02532ed7244e1f69193b4ad","lessThan":"35f991d685feafd27255bd33272512c434e52527","status":"affected","versionType":"git"},{"version":"41fd2fec56db2564f02532ed7244e1f69193b4ad","lessThan":"c48b741277b01b2c3b4ecccedc72fc575b71dc04","status":"affected","versionType":"git"},{"version":"41fd2fec56db2564f02532ed7244e1f69193b4ad","lessThan":"e8ac5e91b1296f65c3d119fac3fa917ff458f811","status":"affected","versionType":"git"},{"version":"41fd2fec56db2564f02532ed7244e1f69193b4ad","lessThan":"94d3982806c7f194b23484befde12934dda23064","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/net/wireless/intel/iwlwifi/mvm/tx.c"],"versions":[{"version":"4.15","status":"affected"},{"version":"0","lessThan":"4.15","status":"unaffected","versionType":"semver"},{"version":"6.6.158","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.111","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.53","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.15","versionEndExcluding":"6.6.158"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.15","versionEndExcluding":"6.12.111"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.15","versionEndExcluding":"6.18.53"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.15","versionEndExcluding":"7.2"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/35f991d685feafd27255bd33272512c434e52527"},{"url":"https://git.kernel.org/stable/c/c48b741277b01b2c3b4ecccedc72fc575b71dc04"},{"url":"https://git.kernel.org/stable/c/e8ac5e91b1296f65c3d119fac3fa917ff458f811"},{"url":"https://git.kernel.org/stable/c/94d3982806c7f194b23484befde12934dda23064"}],"title":"wifi: iwlwifi: mvm: fix out-of-bounds tid_data access in BA notif","x_generator":{"engine":"bippy-1.2.0"}}}}