{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-93804","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-18T17:59:28.790Z","datePublished":"2026-09-24T16:02:38.223Z","dateUpdated":"2026-09-25T12:43:11.708Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-25T12:43:11.708Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: mac80211: ibss: wait for in-flight TX on disconnect\n\nWhile leaving an IBSS in ieee80211_ibss_disconnect() mac80211 flushes\nstations, turns the carrier off and immediately tells the driver to\nleave as well. While there may be synchronize_net() in station flush\nand in this code later, packets can still be transmitted due to\ncross-CPU race conditions after carrier off is set.\nTherefore, it's possible for a race to happen where a TX to the\ndriver occurs while or after telling it to leave the IBSS. This can\nbe confusing to drivers, and in the case of iwlwifi leads to an\nattempt to use invalid queues.\n\nMove netif_carrier_off() to occur before sta_info_flush() during\nIBSS disconnect, and add synchronize_net() if flushing didn't,\nso that the synchronize_net() always happens between turning the\ncarrier off and telling the driver, avoiding this race."}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["net/mac80211/ibss.c"],"versions":[{"version":"86a2ea4134b48f6371103cfceb521bf2d2bf76cd","lessThan":"20a3fb5e1a95caa34896853ca17a50d21c754969","status":"affected","versionType":"git"},{"version":"86a2ea4134b48f6371103cfceb521bf2d2bf76cd","lessThan":"b3451e6971248250312ad32dd7f63cc9f0a925f5","status":"affected","versionType":"git"},{"version":"86a2ea4134b48f6371103cfceb521bf2d2bf76cd","lessThan":"d0e69d9afa59b93c30294eba89b1f15f69e91105","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["net/mac80211/ibss.c"],"versions":[{"version":"3.3","status":"affected"},{"version":"0","lessThan":"3.3","status":"unaffected","versionType":"semver"},{"version":"6.12.111","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.53","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.3","versionEndExcluding":"6.12.111"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.3","versionEndExcluding":"6.18.53"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.3","versionEndExcluding":"7.2"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/20a3fb5e1a95caa34896853ca17a50d21c754969"},{"url":"https://git.kernel.org/stable/c/b3451e6971248250312ad32dd7f63cc9f0a925f5"},{"url":"https://git.kernel.org/stable/c/d0e69d9afa59b93c30294eba89b1f15f69e91105"}],"title":"wifi: mac80211: ibss: wait for in-flight TX on disconnect","x_generator":{"engine":"bippy-1.2.0"}}}}