SB20260918148 - Off-by-one in Linux kernel iwlwifi mvm driver
Published: September 18, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Off-by-one (CVE-ID: CVE-2026-93064)
CWE-ID: CWE-193 - Off-by-one Error
CVSSv4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause memory corruption.
The vulnerability exists due to an off-by-one error in iwl_mvm_frob_txf_key_iter() when sanitizing TXF keys. A local user can trigger sanitization of a fully matched key to cause memory corruption.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/1af000d75b1c96f7cbdf23f14d0ee1c51b12f8e6
- https://git.kernel.org/stable/c/2a77cb320e3998afa5e1ed0e95908b226aae9ed6
- https://git.kernel.org/stable/c/4c582ed61325135f841ca93667d7551a8e31e58d
- https://git.kernel.org/stable/c/5bcc933c6d47d795dab27458b9001c2d97130fd3
- https://git.kernel.org/stable/c/c9d8641aea01c3b2516483e128e1f557cfbcf44a
- https://git.kernel.org/stable/c/f6a6c01cbc046f68e6916a7e047a1bc881c8c9ab