{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-93802","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-18T17:59:28.789Z","datePublished":"2026-09-24T16:02:36.341Z","dateUpdated":"2026-10-03T10:57:35.833Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-10-03T10:57:35.833Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: rsi: validate beacon length before fixed buffer copy\n\nrsi_prepare_beacon() copies the mac80211 beacon frame after\nFRAME_DESC_SZ into a management skb whose usable tailroom may be smaller\nthan MAX_MGMT_PKT_SIZE after alignment.\n\nValidate the beacon length against the actual tailroom before the copy\nand skb_put(). Leave ownership of the management skb with the caller on\nerror, matching the existing rsi_send_beacon() cleanup path."}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/net/wireless/rsi/rsi_91x_hal.c"],"versions":[{"version":"d26a9559403c7c3ec3b430f5825bc22c3d40abdb","lessThan":"795ba65f46fe44061f1195951c122cc8ec685d44","status":"affected","versionType":"git"},{"version":"d26a9559403c7c3ec3b430f5825bc22c3d40abdb","lessThan":"66a964432b2758a4cf69962366e37581d6e70632","status":"affected","versionType":"git"},{"version":"d26a9559403c7c3ec3b430f5825bc22c3d40abdb","lessThan":"7f99742c3c2801f8033d8b7a0a58254d7f24fb1e","status":"affected","versionType":"git"},{"version":"d26a9559403c7c3ec3b430f5825bc22c3d40abdb","lessThan":"f08d7f3c916335a0e539f1c45c130615967fac47","status":"affected","versionType":"git"},{"version":"d26a9559403c7c3ec3b430f5825bc22c3d40abdb","lessThan":"87710ad633ce4588aec88611d0d0745eb33a6991","status":"affected","versionType":"git"},{"version":"d26a9559403c7c3ec3b430f5825bc22c3d40abdb","lessThan":"266f195d5a14eec6c482fd09fbc924584c3371a7","status":"affected","versionType":"git"},{"version":"d26a9559403c7c3ec3b430f5825bc22c3d40abdb","lessThan":"8ecdeb8b8a33b22c597299043c0dcfce50beb9ea","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/net/wireless/rsi/rsi_91x_hal.c"],"versions":[{"version":"4.14","status":"affected"},{"version":"0","lessThan":"4.14","status":"unaffected","versionType":"semver"},{"version":"5.10.271","lessThanOrEqual":"5.10.*","status":"unaffected","versionType":"semver"},{"version":"5.15.222","lessThanOrEqual":"5.15.*","status":"unaffected","versionType":"semver"},{"version":"6.1.189","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.158","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.111","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.53","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.14","versionEndExcluding":"5.10.271"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.14","versionEndExcluding":"5.15.222"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.14","versionEndExcluding":"6.1.189"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.14","versionEndExcluding":"6.6.158"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.14","versionEndExcluding":"6.12.111"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.14","versionEndExcluding":"6.18.53"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.14","versionEndExcluding":"7.2"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/795ba65f46fe44061f1195951c122cc8ec685d44"},{"url":"https://git.kernel.org/stable/c/66a964432b2758a4cf69962366e37581d6e70632"},{"url":"https://git.kernel.org/stable/c/7f99742c3c2801f8033d8b7a0a58254d7f24fb1e"},{"url":"https://git.kernel.org/stable/c/f08d7f3c916335a0e539f1c45c130615967fac47"},{"url":"https://git.kernel.org/stable/c/87710ad633ce4588aec88611d0d0745eb33a6991"},{"url":"https://git.kernel.org/stable/c/266f195d5a14eec6c482fd09fbc924584c3371a7"},{"url":"https://git.kernel.org/stable/c/8ecdeb8b8a33b22c597299043c0dcfce50beb9ea"}],"title":"wifi: rsi: validate beacon length before fixed buffer copy","x_generator":{"engine":"bippy-1.2.0"}}}}