Race condition in Linux kernel - CVE-2026-93804

 

Race condition in Linux kernel - CVE-2026-93804

Published: September 25, 2026


Vulnerability identifier: #VU152086
CSH Severity: Low
CVSS v4: 0 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-93804
CWE-ID: CWE-362
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to cause packets to be transmitted to the driver after it has been told to leave an IBSS.

The vulnerability exists due to a race condition in ieee80211_ibss_disconnect() in mac80211 when disconnecting from an IBSS while transmissions are in flight. A local user can initiate an IBSS disconnect while packets are still being transmitted to cause packets to be transmitted to the driver after it has been told to leave an IBSS.


Affected software

Linux kernel

How to mitigate CVE-2026-93804

Install security update from vendor's repository.

Linux kernel - update to 7.0 rc3

External References

Related Security Bulletins