← All Advisories

CVE-2026-93784

Last refreshed2026-10-03

Status: UPDATED  |  Advisory ID: CVE-2026-93784

Key Details

CVECVE-2026-93784
Affected productsLinux Linux

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
LinuxLinux
SubsystemsGeneral OT
SectorsMultiple

What to Know

In the Linux kernel, the following vulnerability has been resolved:

wifi: cfg80211: validate IEs in cfg80211_wext_siwgenie()

The KASAN allocation trace shows that a malformed IE buffer is

stored via SIOCSIWGENIE (cfg80211_wext_siwgenie()) without any

validation. The crash trace shows that a subsequent SIOCSIWESSID

triggers a connection attempt which calls cfg80211_sme_get_conn_ies()

to process the stored IE buffer, causing:

- An out-of-bounds read in skip_ie() which reads ies[pos+1]

(the length byte) past the end of the 1-byte buffer.

- An integer underflow in the memcpy size argument when offs

returned by ieee80211_ie_split() exceeds ies_len, causing

unsigned subtraction to wrap to SIZE_MAX and triggering a

fortify panic.

Fix this by validating the IE buffer in cfg80211_wext_siwgenie()

before storing it.

[drop unnecessary ie_len check, update commit message] (NVD)

What to Do

Monitor Linux's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-93784
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-93784