« Volver al listado

CVE-2026-93807

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

wifi: rsi: avoid reading TKIP MIC keys for non-TKIP ciphers

rsi_hal_load_key() copies tx_mic_key and rx_mic_key from data[16] and data[24] whenever key data is present. Those offsets are only part of the 32-byte TKIP key layout. Shorter keys used by other ciphers, such as CCMP, do not provide those bytes, so the unconditional copies can read past the supplied key buffer.

Only copy the MIC keys for TKIP, and reject malformed TKIP keys that are shorter than the expected 32-byte layout.

[drop useless length check]

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-93807",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "dad0d04fa7ba41ce603a01e8e64967650303e9a2",
              "lessThan": "6937b06d55b528e961feff8cc083b97ede622e02",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "dad0d04fa7ba41ce603a01e8e64967650303e9a2",
              "lessThan": "ebd7172f8c4edc232738ef50338fb773c6f6c208",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "dad0d04fa7ba41ce603a01e8e64967650303e9a2",
              "lessThan": "6b6690ac5c35e803df14afdc44312d11e8a60893",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "dad0d04fa7ba41ce603a01e8e64967650303e9a2",
              "lessThan": "5207727e53fba1e3a6fce9b2c15b6b8b06c6438b",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "dad0d04fa7ba41ce603a01e8e64967650303e9a2",
              "lessThan": "5902e3c08c63d65724772f74d65b9fb032625dca",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "dad0d04fa7ba41ce603a01e8e64967650303e9a2",
              "lessThan": "55b86ef6c2e68879ffd95203b011ef42a013ab88",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "dad0d04fa7ba41ce603a01e8e64967650303e9a2",
              "lessThan": "843fe9bc583b7686ca68312ac9319c9240a73c03",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "drivers/net/wireless/rsi/rsi_91x_mgmt.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "3.15"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "3.15",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "5.10.271",
              "versionType": "semver",
              "lessThanOrEqual": "5.10.*"
            },
            {
              "status": "unaffected",
              "version": "5.15.222",
              "versionType": "semver",
              "lessThanOrEqual": "5.15.*"
            },
            {
              "status": "unaffected",
              "version": "6.1.189",
              "versionType": "semver",
              "lessThanOrEqual": "6.1.*"
            },
            {
              "status": "unaffected",
              "version": "6.6.158",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.111",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.53",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.2",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "drivers/net/wireless/rsi/rsi_91x_mgmt.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-24T17:17:13.683",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/5207727e53fba1e3a6fce9b2c15b6b8b06c6438b",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/55b86ef6c2e68879ffd95203b011ef42a013ab88",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/5902e3c08c63d65724772f74d65b9fb032625dca",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/6937b06d55b528e961feff8cc083b97ede622e02",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/6b6690ac5c35e803df14afdc44312d11e8a60893",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/843fe9bc583b7686ca68312ac9319c9240a73c03",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/ebd7172f8c4edc232738ef50338fb773c6f6c208",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: rsi: avoid reading TKIP MIC keys for non-TKIP ciphers\n\nrsi_hal_load_key() copies tx_mic_key and rx_mic_key from data[16] and\ndata[24] whenever key data is present. Those offsets are only part of\nthe 32-byte TKIP key layout. Shorter keys used by other ciphers, such as\nCCMP, do not provide those bytes, so the unconditional copies can read\npast the supplied key buffer.\n\nOnly copy the MIC keys for TKIP, and reject malformed TKIP keys that are\nshorter than the expected 32-byte layout.\n\n[drop useless length check]"
    }
  ],
  "lastModified": "2026-10-03T11:17:50.480",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}