SB2026092580 - Reliance on undefined behavior in Linux kernel iwlwifi fw driver



SB2026092580 - Reliance on undefined behavior in Linux kernel iwlwifi fw driver

Published: September 25, 2026

Security Bulletin ID SB2026092580
CSH Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Physical access
Highest impact Information disclosure

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Reliance on undefined behavior (CVE-ID: CVE-2026-93788)

CWE-ID: CWE-758 - Reliance on Undefined, Unspecified, or Implementation-Defined Behavior

CVSSv4: 0 [CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows an attacker with physical access to trigger undefined behavior.

The vulnerability exists due to improper bounds checking in the WGDS table revision index handling when processing WGDS tables reporting an invalid revision value. An attacker with physical access can cause the kernel to process a WGDS table with an invalid revision value to trigger undefined behavior.


Remediation

Install update from vendor's website.