目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1359 元

100%

CVE-2026-93805— WiFi cfg80211 验证rx/tx MLME回调帧长度

一分钟漏洞结论

影响对象
Linux Linux
利用判断
尚无明确在野利用证据,仍需结合暴露面评估
建议动作
优先检查厂商安全公告和参考链接中的修复版本;无法立即升级时,限制受影响服务暴露并加强监测。

在 Linux 内核中,已修复以下漏洞: wifi: cfg80211: 在访问前验证 rx/tx MLME 回调帧的长度 和 在拒绝短于帧控制字段(frame-control field)的帧之前会调用跟踪点(tracepoints)。此后,它们仅在分发到假设固定字段存在的子类型处理程序之前,要求长度 。 触发此漏洞的帧长度并不短于 2 字节;而是相对于其子类型而言过短。以 mwifiex 为例,这是一个在-tree 中的具体实例: 仅在将帧传递给 之前,要求存在一个 4-地址的 加上 2 字节的固件长度前缀。在

AI 预测 5.5 利用难度: 中等 EPSS 0.17% · P6

影响版本矩阵 14

厂商产品 版本范围状态
Linux Linux 6829c878ecd24ff0ae41b4668c7e9d0f11b66942< 6eb4bd50be53f5afbabb3a3b5153276e08fa7a4a affected
6829c878ecd24ff0ae41b4668c7e9d0f11b66942< ce2a3be6909462f49c34de96be71f0ad5f0d573f affected
6829c878ecd24ff0ae41b4668c7e9d0f11b66942< 6bdf4dcff98df634e04ebf99f52027a48d7f78ff affected
6829c878ecd24ff0ae41b4668c7e9d0f11b66942< 0ec738a0d361d7eb37188117166d201f9df622d3 affected
6829c878ecd24ff0ae41b4668c7e9d0f11b66942< 8f4127a93cf60d561ad39849a9ac763ba0e14db5 affected
6829c878ecd24ff0ae41b4668c7e9d0f11b66942< d5e4586546974179feca305a94e07fac3e9727fe affected
2.6.32 affected
< 2.6.32 unaffected
… +6 条更多
获取后续新漏洞提醒 登录后订阅

一、 漏洞 CVE-2026-93805 基础信息

漏洞信息

对漏洞内容有疑问?看看神龙的深度分析是否有帮助!
查看神龙十问 ↗

尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。

Vulnerability Title
wifi: cfg80211: validate rx/tx MLME callback frame lengths before access
来源: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: wifi: cfg80211: validate rx/tx MLME callback frame lengths before access cfg80211_rx_mlme_mgmt() and cfg80211_tx_mlme_mgmt() call tracepoints before rejecting frames shorter than the frame-control field. After that, they only require len >= 2 before dispatching into subtype handlers that assume their fixed fields are present. The frames that trip this are not shorter than 2 bytes; they are short relative to their subtype. mwifiex is a concrete in-tree example on the length side: mwifiex_process_mgmt_packet() only requires a 4-address ieee80211_hdr plus the 2-byte firmware length prefix before handing the frame to cfg80211_rx_mlme_mgmt(). After stripping the length prefix and removing addr4, pkt_len can be exactly 24: a bare 3-address management header with no reason-code body. The existing WARN_ON(len < 2) does not fire on such a frame, and cfg80211_process_deauth() then reads u.deauth.reason_code as a two-byte access starting at offset 24, immediately past the 24-byte buffer. Add a frame-control length gate, then validate each subtype's minimum frame size in an if/else-if chain that mirrors the dispatch logic. Trace only after the frame is known to be well-formed. Side effects of this change: - The WARN_ON(len < 2) is dropped. It only guarded the frame_control read, never the subtype fixed fields, and it does not fire on the frames that actually trigger the out-of-bounds read (which are >= 2). The len >= 2 check is kept as the guard before dereferencing frame_control, but without the warning: these are exported callbacks and a malformed frame from a driver should be dropped silently rather than backtraced. - cfg80211_tx_mlme_mgmt() previously routed every non-deauth subtype through disassociation handling; it now silently ignores unrecognised subtypes.
来源: CVE Program / CVE List V5
CVSS Information
N/A
来源: CVE Program / CVE List V5
Vulnerability Type
N/A
来源: CVE Program / CVE List V5

受影响产品

厂商 产品 影响版本 CPE 订阅
Linux Linux 6829c878ecd24ff0ae41b4668c7e9d0f11b66942 ~ 6eb4bd50be53f5afbabb3a3b5153276e08fa7a4a -
Linux Linux 2.6.32 -

二、漏洞 CVE-2026-93805 的公开POC

# POC 描述 源链接 神龙链接
AI 生成 POC 高级

未找到公开 POC。

登录以生成 AI POC

三、漏洞 CVE-2026-93805 的情报信息

请登录查看更多情报信息。

CVE-2026-93805 补丁与修复 (6)

同批安全公告 · Linux · 2026-09-24 · 共 234 条

CVE-2026-93207 9.8 CRITICAL SUNRPC svcauth_gss_decode_credbody() 存在安全漏洞
CVE-2026-97413 9.8 CRITICAL Linux RDMA/rtrs-srv整数下溢漏洞
CVE-2026-93228 9.1 CRITICAL svcrdma 拒绝段计数为0的写入/回复块漏洞
CVE-2026-93793 8.8 HIGH iwlwifi 驱动 TX_CMD 响应布局验证漏洞
CVE-2026-93790 8.8 HIGH iwlwifi 驱动 BA 通知中 tid_data 越界访问漏洞
CVE-2026-93799 8.8 HIGH iwlwifi mvm BA窗口状态通知中sta_id验证漏洞
CVE-2026-97442 8.8 HIGH ath11k无线驱动rx_h_undecap_nwifi无效数据访问漏洞
CVE-2026-93806 8.8 HIGH wifi: cfg80211 关联响应长度验证漏洞
CVE-2026-97509 8.8 HIGH Thunderbolt 服务期间保持 XDomain 引用漏洞
CVE-2026-97409 8.8 HIGH Linux NVMe-oF目标未初始化前取消请求漏洞
CVE-2026-93280 8.8 HIGH Greybus 音频拓扑边界检查漏洞
CVE-2026-93284 8.8 HIGH drm/pagemap 迁移错误前未解除 dma 映射
CVE-2026-97451 8.4 HIGH ACPICA mid_op 整数溢出漏洞
CVE-2026-97452 8.4 HIGH ACPICA:防止添加无效引用
CVE-2026-97455 8.4 HIGH ACPICA acpi_ds_terminate_control_method 使用后释放漏洞
CVE-2026-97450 8.4 HIGH ACPICA 双重验证处理器对象类型漏洞
CVE-2026-93827 8.4 HIGH virtio-fs 队列设置失败时双重释放漏洞
CVE-2026-97433 8.2 HIGH NVMe 验证 FDP 配置描述符大小
CVE-2026-93224 8.1 HIGH svcrdma 接受失败时未配对 rn_unregister 漏洞
CVE-2026-93787 8.1 HIGH CIFS cifs_filldir 中目录项名称越界访问漏洞

显示前 20 条,共 234 条。 查看全部 &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2026-93805

暂无评论


发表评论