« Volver al listado

CVE-2026-93790

Estado: RecibidaAlta (8.8)—

In the Linux kernel, the following vulnerability has been resolved:

wifi: iwlwifi: mvm: fix out-of-bounds tid_data access in BA notif

mvmsta->tid_data was indexed by the TFD loop counter 'i' instead of the actual TID value 'tid'. This writes lq_color into a random tid_data slot unrelated to the BA entry. Since multi-TID blockack is not really in use, 'i' was always 0 and no harm was done. Add a out-of-bound check before accessing the array.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

Acceso a red adyacente (AV:A) en wifi iwlwifi del kernel Linux. Out-of-bounds en tid_data podría causar DoS al corromper memoria. Confianza moderada: vector sugiere T1210, pero vulnerabilidad es principalmente defensa/estabilidad, no ejecución clara.

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-93790",
  "cveTags": [],
  "metrics": {
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 8.8,
          "attackVector": "ADJACENT_NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "41fd2fec56db2564f02532ed7244e1f69193b4ad",
              "lessThan": "35f991d685feafd27255bd33272512c434e52527",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "41fd2fec56db2564f02532ed7244e1f69193b4ad",
              "lessThan": "c48b741277b01b2c3b4ecccedc72fc575b71dc04",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "41fd2fec56db2564f02532ed7244e1f69193b4ad",
              "lessThan": "e8ac5e91b1296f65c3d119fac3fa917ff458f811",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "41fd2fec56db2564f02532ed7244e1f69193b4ad",
              "lessThan": "94d3982806c7f194b23484befde12934dda23064",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "drivers/net/wireless/intel/iwlwifi/mvm/tx.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "4.15"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "4.15",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.6.158",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.111",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.53",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.2",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "drivers/net/wireless/intel/iwlwifi/mvm/tx.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-24T17:17:11.710",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/35f991d685feafd27255bd33272512c434e52527",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/94d3982806c7f194b23484befde12934dda23064",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/c48b741277b01b2c3b4ecccedc72fc575b71dc04",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/e8ac5e91b1296f65c3d119fac3fa917ff458f811",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: iwlwifi: mvm: fix out-of-bounds tid_data access in BA notif\n\nmvmsta->tid_data was indexed by the TFD loop counter 'i' instead of\nthe actual TID value 'tid'. This writes lq_color into a random tid_data\nslot unrelated to the BA entry.\nSince multi-TID blockack is not really in use, 'i' was always 0 and no\nharm was done.\nAdd a out-of-bound check before accessing the array."
    }
  ],
  "lastModified": "2026-10-03T11:17:48.677",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}