Out-of-bounds read in Linux kernel - CVE-2026-93793
Published: September 25, 2026
Vulnerability details
The vulnerability allows a local user to cause an out-of-bounds read.
The vulnerability exists due to improper length validation in TX_CMD response parsing in the iwlwifi mvm driver when processing TX_CMD responses with payloads shorter than the frame_count-dependent status layout. A local user can supply a malformed TX_CMD response to cause an out-of-bounds read.