In the Linux kernel, the following vulnerability has been resolved:
wifi: cfg80211: validate IEs in cfg80211_wext_siwgenie()
The KASAN allocation trace shows that a malformed IE buffer is
stored via SIOCSIWGENIE (cfg80211_wext_siwgenie()) without any
validation. The crash trace shows that a subsequent SIOCSIWESSID
triggers a connection attempt which calls cfg80211_sme_get_conn_ies()
to process the stored IE buffer, causing:
- An out-of-bounds read in skip_ie() which reads ies[pos+1]
(the length byte) past the end of the 1-byte buffer.
- An integer underflow in the memcpy size argument when offs
returned by ieee80211_ie_split() exceeds ies_len, causing
unsigned subtraction to wrap to SIZE_MAX and triggering a
fortify panic.
Fix this by validating the IE buffer in cfg80211_wext_siwgenie()
before storing it.
[drop unnecessary ie_len check, update commit message]
CVE-2026-93784
NONE
EPSS 0.17%
Обновлено 25 сентября 2026
Linux
https://git.kernel.org/stable/c/01cc395cecfaa73134d39fb9a401d9605d8bb2c5
416baaa9-dc9f-4396-8d5f-8c081fb06d67
https://git.kernel.org/stable/c/a2f5286ca4f304d3fd469f01b96b518608912a5c
416baaa9-dc9f-4396-8d5f-8c081fb06d67
https://git.kernel.org/stable/c/c970879e03b23a27df42caf7ba506485a165fb96
416baaa9-dc9f-4396-8d5f-8c081fb06d67
Сводка
CVE ID
CVE-2026-93784
Опубликовано
24 сентября, 2026
Поставщик
Linux
Уровень угрозы
NONE
Вероятность атаки (EPSS)
Шанс использования
0.17%
Вероятность использования в ближайшие 30 дней
Уровень риска:
Опаснее 5.3% всех уязвимостей
Стандартный цикл обновлений
Ущерб
Минимальное воздействие
Ссылка
Перейти к источнику