CVE-2026-93807
In the Linux kernel, the following vulnerability has been resolved:
wifi: rsi: avoid reading TKIP MIC keys for non-TKIP ciphers
rsi_hal_load_key() copies tx_mic_key and rx_mic_key from data[16] and data[24] whenever key data is present. Those offsets are only part of the 32-byte TKIP key layout. Shorter keys used by other ciphers, such as CCMP, do not provide those bytes, so the unconditional copies can read past the supplied key buffer.
Only copy the MIC keys for TKIP, and reject malformed TKIP keys that are shorter than the expected 32-byte layout.
[drop useless length check]
CVSS
NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.17%
- Percentil entre todas las CVEs puntuadas: 6
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
Referencias
- https://git.kernel.org/stable/c/5207727e53fba1e3a6fce9b2c15b6b8b06c6438b
- https://git.kernel.org/stable/c/55b86ef6c2e68879ffd95203b011ef42a013ab88
- https://git.kernel.org/stable/c/5902e3c08c63d65724772f74d65b9fb032625dca
- https://git.kernel.org/stable/c/6937b06d55b528e961feff8cc083b97ede622e02
- https://git.kernel.org/stable/c/6b6690ac5c35e803df14afdc44312d11e8a60893
- https://git.kernel.org/stable/c/843fe9bc583b7686ca68312ac9319c9240a73c03
- https://git.kernel.org/stable/c/ebd7172f8c4edc232738ef50338fb773c6f6c208
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-93807",
"cveTags": [],
"metrics": {},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "dad0d04fa7ba41ce603a01e8e64967650303e9a2",
"lessThan": "6937b06d55b528e961feff8cc083b97ede622e02",
"versionType": "git"
},
{
"status": "affected",
"version": "dad0d04fa7ba41ce603a01e8e64967650303e9a2",
"lessThan": "ebd7172f8c4edc232738ef50338fb773c6f6c208",
"versionType": "git"
},
{
"status": "affected",
"version": "dad0d04fa7ba41ce603a01e8e64967650303e9a2",
"lessThan": "6b6690ac5c35e803df14afdc44312d11e8a60893",
"versionType": "git"
},
{
"status": "affected",
"version": "dad0d04fa7ba41ce603a01e8e64967650303e9a2",
"lessThan": "5207727e53fba1e3a6fce9b2c15b6b8b06c6438b",
"versionType": "git"
},
{
"status": "affected",
"version": "dad0d04fa7ba41ce603a01e8e64967650303e9a2",
"lessThan": "5902e3c08c63d65724772f74d65b9fb032625dca",
"versionType": "git"
},
{
"status": "affected",
"version": "dad0d04fa7ba41ce603a01e8e64967650303e9a2",
"lessThan": "55b86ef6c2e68879ffd95203b011ef42a013ab88",
"versionType": "git"
},
{
"status": "affected",
"version": "dad0d04fa7ba41ce603a01e8e64967650303e9a2",
"lessThan": "843fe9bc583b7686ca68312ac9319c9240a73c03",
"versionType": "git"
}
],
"programFiles": [
"drivers/net/wireless/rsi/rsi_91x_mgmt.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "3.15"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "3.15",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "5.10.271",
"versionType": "semver",
"lessThanOrEqual": "5.10.*"
},
{
"status": "unaffected",
"version": "5.15.222",
"versionType": "semver",
"lessThanOrEqual": "5.15.*"
},
{
"status": "unaffected",
"version": "6.1.189",
"versionType": "semver",
"lessThanOrEqual": "6.1.*"
},
{
"status": "unaffected",
"version": "6.6.158",
"versionType": "semver",
"lessThanOrEqual": "6.6.*"
},
{
"status": "unaffected",
"version": "6.12.111",
"versionType": "semver",
"lessThanOrEqual": "6.12.*"
},
{
"status": "unaffected",
"version": "6.18.53",
"versionType": "semver",
"lessThanOrEqual": "6.18.*"
},
{
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"drivers/net/wireless/rsi/rsi_91x_mgmt.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-09-24T17:17:13.683",
"references": [
{
"url": "https://git.kernel.org/stable/c/5207727e53fba1e3a6fce9b2c15b6b8b06c6438b",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/55b86ef6c2e68879ffd95203b011ef42a013ab88",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/5902e3c08c63d65724772f74d65b9fb032625dca",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/6937b06d55b528e961feff8cc083b97ede622e02",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/6b6690ac5c35e803df14afdc44312d11e8a60893",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/843fe9bc583b7686ca68312ac9319c9240a73c03",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/ebd7172f8c4edc232738ef50338fb773c6f6c208",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: rsi: avoid reading TKIP MIC keys for non-TKIP ciphers\n\nrsi_hal_load_key() copies tx_mic_key and rx_mic_key from data[16] and\ndata[24] whenever key data is present. Those offsets are only part of\nthe 32-byte TKIP key layout. Shorter keys used by other ciphers, such as\nCCMP, do not provide those bytes, so the unconditional copies can read\npast the supplied key buffer.\n\nOnly copy the MIC keys for TKIP, and reject malformed TKIP keys that are\nshorter than the expected 32-byte layout.\n\n[drop useless length check]"
}
],
"lastModified": "2026-10-03T11:17:50.480",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}