{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-93793","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-18T17:59:28.789Z","datePublished":"2026-09-24T16:02:26.708Z","dateUpdated":"2026-09-25T12:42:59.445Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-25T12:42:59.445Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: iwlwifi: mvm: validate TX_CMD response layout\n\nTX_CMD parsing uses frame_count to walk status entries and then\nread the trailing SCD SSN. Make the minimum-length check follow\nthat exact runtime layout calculation before parsing the payload.\n\nFor new TX API, reject TX_CMD responses with frame_count != 1 and\nwarn/return in the aggregation handler to document that aggregated\naccounting is expected via BA notifications."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:A - The malformed input is a firmware TX_CMD (REPLY_TX 0x1c) notification DMA'd from the Intel WiFi NIC: iwl_pcie_rx_handle() → iwl_op_mode_rx() → iwl_mvm_rx()/iwl_mvm_rx_mq() → iwl_mvm_rx_common() → RX_HANDLER(TX_CMD, iwl_mvm_rx_tx_cmd). Those bytes are not a routable IP payload; WiFi host-device range is Adjacent.\nAC:L - iwl_mvm_rx_tx_cmd() is RX_HANDLER_SYNC; a single TX_CMD whose firmware-chosen frame_count makes iwl_mvm_tx_resp_min_len() exceed iwl_rx_packet_payload_len() (or frame_count!=1 on the new TX API) is parsed immediately, with no race or victim state the sender cannot induce by posting that notification.\nPR:N - iwl_mvm_rx_common() only checks pkt_len against sizeof(struct iwl_tx_resp) then calls iwl_mvm_rx_tx_cmd() with no uid, capability, or 802.11 authentication check; TX_CMD is in no_reclaim_cmds as a ucode-originated notif. An RF-adjacent attacker needs no host account.\nUI:N - The NAPI path consumes TX_CMD automatically when firmware posts a TX completion while the interface is up; iwl_mvm_rx_tx_cmd() does not require the victim to mount, open a file, or take any extra action at trigger time.\nS:U - iwl_mvm_get_scd_ssn() and iwl_trans_reclaim() from iwl_mvm_rx_tx_cmd_single() operate on host iwlwifi RX pages and TX queues inside the same kernel authority; this is not a KVM/Xen escape or an IOMMU/DMA-boundary bypass.\nC:H - iwl_mvm_get_scd_ssn() does le32_to_cpup((__le32 *)agg_status + frame_count) with no payload check, and iwl_mvm_rx_tx_cmd_agg_dbg() walks status[frame_count] (u8, up to 255 entries). That is an out-of-bounds read past the TX_CMD into the RX page, and a poisoned SSN into iwl_trans_reclaim() is UAF-class.\nI:H - The over-read SCD SSN is passed to iwl_trans_reclaim()/iwl_pcie_reclaim(), which unmaps TFDs, NULLs txq->entries[].skb, and advances txq->read_ptr, completing in-flight TX buffers early. That is an out-of-bounds-fed free/write of live TX objects, not a bounded status update.\nA:H - iwl_pcie_reclaim() WARNs on a missing skb or cmd-queue txq_id, and an SSN whose last_to_free is not in iwl_txq_used() desynchronizes the TX ring; walking status[frame_count] past the mapped RX buffer can oops. Kernel WARN/oops or a firmware-assert restart is high availability impact."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/net/wireless/intel/iwlwifi/mvm/tx.c"],"versions":[{"version":"8ca151b568b67a7b72dcfc6ee6ea7c107ddd795c","lessThan":"fc14f5fe8a4374ed1088cfbddc1dae4d16c9935b","status":"affected","versionType":"git"},{"version":"8ca151b568b67a7b72dcfc6ee6ea7c107ddd795c","lessThan":"4d942dfc13aec393e003ab28ff58db744c26e6eb","status":"affected","versionType":"git"},{"version":"8ca151b568b67a7b72dcfc6ee6ea7c107ddd795c","lessThan":"8d70881707b47353359df57df12f6de67fdacdd2","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/net/wireless/intel/iwlwifi/mvm/tx.c"],"versions":[{"version":"3.9","status":"affected"},{"version":"0","lessThan":"3.9","status":"unaffected","versionType":"semver"},{"version":"6.12.111","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.53","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.9","versionEndExcluding":"6.12.111"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.9","versionEndExcluding":"6.18.53"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.9","versionEndExcluding":"7.2"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/fc14f5fe8a4374ed1088cfbddc1dae4d16c9935b"},{"url":"https://git.kernel.org/stable/c/4d942dfc13aec393e003ab28ff58db744c26e6eb"},{"url":"https://git.kernel.org/stable/c/8d70881707b47353359df57df12f6de67fdacdd2"}],"title":"wifi: iwlwifi: mvm: validate TX_CMD response layout","x_generator":{"engine":"bippy-1.2.0"}}}}