Out-of-bounds write in Linux kernel - CVE-2026-93790
Published: September 25, 2026
Vulnerability details
The vulnerability allows a local user to write outside the bounds of an array.
The vulnerability exists due to improper array index validation in the iwl_mvm_rx_ba_notif handler when processing compressed block acknowledgment notifications. A local user can trigger processing of a compressed block acknowledgment notification containing an invalid TID to write outside the bounds of an array.
Multi-TID block acknowledgment is not generally in use.