{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-93799","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-18T17:59:28.789Z","datePublished":"2026-09-24T16:02:32.174Z","dateUpdated":"2026-10-03T10:57:33.642Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-10-03T10:57:33.642Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: iwlwifi: mvm: validate sta_id in BA window status notif\n\nBA_WINDOW_STATUS_NOTIFICATION_ID extracts a 5-bit sta_id from the\nfirmware notification and uses it to index fw_id_to_mac_id[] without\nbounds checking. Validate sta_id before array access to prevent\nout-of-bounds indexing."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:A - The bad 5-bit sta_id is in BA_WINDOW_STATUS_NOTIFICATION (cmd 0x13) DMA'd from the Intel WiFi NIC. iwl_pcie_rx_handle_rb → iwl_op_mode_rx → iwl_mvm_rx → iwl_mvm_rx_common dispatches that notif to iwl_mvm_window_status_notif, which reports received MPDUs in the BA window; that is WiFi radio range, not a routable IP protocol.\nAC:L - iwl_mvm_window_status_notif uses notif->ra_tid's 5-bit sta_id with no race or extra kernel gate beyond VALID and mpdu_rx_count != 0. A nearby peer that sends aggregated 802.11 traffic causes firmware to emit this BA window notif; once sta_id >= num_stations the fw_id_to_mac_id[] OOB is deterministic.\nPR:N - iwl_mvm_window_status_notif is an RX_HANDLER_SYNC handler with no capability, socket, or 802.11 authentication check; iwl_mvm_rx_common invokes it from NAPI as soon as cmd 0x13 arrives. A radio-range attacker needs no host account.\nUI:N - The BA_WINDOW_STATUS_NOTIFICATION is processed automatically in iwl_pcie_napi_poll / iwl_mvm_rx_common on an already-up Intel WiFi interface; the attacker does not need the victim to open a file, mount media, or click through a prompt.\nS:U - The OOB index and the later type-confused ieee80211_mark_rx_ba_filtered_frames() call stay inside iwlwifi/mac80211 kernel memory on the same host; they do not cross a VM, IOMMU, or sandbox boundary.\nC:H - sta_id is 5 bits (0-31) but fw_id_to_mac_id[] has IWL_STATION_COUNT_MAX (16) entries, so sta_id 16-31 reads adjacent fw_id_to_link_sta[] pointers as ieee80211_sta*. ieee80211_mark_rx_ba_filtered_frames() then container_of()s that into sta_info and follows sta->sdata and tid_rx, a type confusion that can disclose kernel memory.\nI:H - The same confused sta_info is used to write tid_agg_rx->head_seq_num and reorder_buf_filtered and to release reorder-buffer frames into ieee80211_rx_handlers(), so the fw_id_to_link_sta versus ieee80211_sta type confusion is a kernel write / RX-injection primitive.\nA:H - Treating an ieee80211_link_sta* as ieee80211_sta* makes container_of() in ieee80211_mark_rx_ba_filtered_frames() compute a bogus sta_info, and the immediate sta->sdata->local dereference in NAPI oopses or panics."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/net/wireless/intel/iwlwifi/mvm/rx.c"],"versions":[{"version":"3af512d6aac7eb6420086f124abb4426f5f4b369","lessThan":"f9938eb95e2ddab4a58d3946a320abcbd60b56a4","status":"affected","versionType":"git"},{"version":"3af512d6aac7eb6420086f124abb4426f5f4b369","lessThan":"bb08fbbbd5568d33069485ecb0a1657f115a4e9f","status":"affected","versionType":"git"},{"version":"3af512d6aac7eb6420086f124abb4426f5f4b369","lessThan":"e35ae757c6462bfd3437bf58121bb721fe1f790c","status":"affected","versionType":"git"},{"version":"3af512d6aac7eb6420086f124abb4426f5f4b369","lessThan":"6aa77efaea9efea92e3090c35ad348fd759a3cf3","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/net/wireless/intel/iwlwifi/mvm/rx.c"],"versions":[{"version":"4.6","status":"affected"},{"version":"0","lessThan":"4.6","status":"unaffected","versionType":"semver"},{"version":"6.6.158","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.111","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.53","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.6","versionEndExcluding":"6.6.158"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.6","versionEndExcluding":"6.12.111"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.6","versionEndExcluding":"6.18.53"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.6","versionEndExcluding":"7.2"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/f9938eb95e2ddab4a58d3946a320abcbd60b56a4"},{"url":"https://git.kernel.org/stable/c/bb08fbbbd5568d33069485ecb0a1657f115a4e9f"},{"url":"https://git.kernel.org/stable/c/e35ae757c6462bfd3437bf58121bb721fe1f790c"},{"url":"https://git.kernel.org/stable/c/6aa77efaea9efea92e3090c35ad348fd759a3cf3"}],"title":"wifi: iwlwifi: mvm: validate sta_id in BA window status notif","x_generator":{"engine":"bippy-1.2.0"}}}}