Integer underflow in Linux kernel - CVE-2026-93789
Published: September 25, 2026
Vulnerability details
The vulnerability allows a local user to cause a length underflow.
The vulnerability exists due to improper validation of aligned TLV lengths in the iwlwifi firmware parser when processing malformed TLVs in a firmware image. A local user can cause the parser to process a firmware image containing malformed TLVs to cause a length underflow.