← All Advisories

CVE-2026-93806

Last refreshed2026-10-03

Status: UPDATED  |  Advisory ID: CVE-2026-93806

Key Details

CVECVE-2026-93806
CVSS Score / Version8.8 (High) / CVSS v3.1
Updated2026-09-25
CVSS VectorCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS Proseattack vector is adjacent; attack complexity is low; privileges required is none; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is high.
Affected productsLinux Linux

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
LinuxLinux
SubsystemsGeneral OT
SectorsMultiple

What to Know

In the Linux kernel, the following vulnerability has been resolved:

wifi: cfg80211: validate assoc response length before status and IE access

cfg80211_rx_assoc_resp() initialises the status and response-IE fields

of cfg80211_connect_resp_params from the management frame before

proving that the frame is long enough for those offsets. S1G and

regular association responses also have different IE offsets, but the

S1G path only patched resp_ie after the unsafe initialiser had already

run.

Defer resp_ie, resp_ie_len, and status to after the link-iteration

loop. Use a bool to remember whether the frame is S1G, then validate

the appropriate minimum length and set all three fields in a single

if/else block. Funnel short-frame and SME-reject cleanup through a

shared free_bss label for the abandon paths. (NVD)

What to Do

Monitor Linux's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-93806
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-93806