Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-93805— wifi: cfg80211: validate rx/tx MLME callback frame lengths before access

Quick assessment

Affected
Linux Linux
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 Linux 内核中,已修复以下漏洞: wifi: cfg80211: 在访问前验证 rx/tx MLME 回调帧的长度 和 在拒绝短于帧控制字段(frame-control field)的帧之前会调用跟踪点(tracepoints)。此后,它们仅在分发到假设固定字段存在的子类型处理程序之前,要求长度 。 触发此漏洞的帧长度并不短于 2 字节;而是相对于其子类型而言过短。以 mwifiex 为例,这是一个在-tree 中的具体实例: 仅在将帧传递给 之前,要求存在一个 4-地址的 加上 2 字节的固件长度前缀。在

AI Predicted 5.5 Difficulty: Moderate EPSS 0.17% · P6

Affected Version Matrix 14

VendorProduct Version RangeStatus
Linux Linux 6829c878ecd24ff0ae41b4668c7e9d0f11b66942< 6eb4bd50be53f5afbabb3a3b5153276e08fa7a4a affected
6829c878ecd24ff0ae41b4668c7e9d0f11b66942< ce2a3be6909462f49c34de96be71f0ad5f0d573f affected
6829c878ecd24ff0ae41b4668c7e9d0f11b66942< 6bdf4dcff98df634e04ebf99f52027a48d7f78ff affected
6829c878ecd24ff0ae41b4668c7e9d0f11b66942< 0ec738a0d361d7eb37188117166d201f9df622d3 affected
6829c878ecd24ff0ae41b4668c7e9d0f11b66942< 8f4127a93cf60d561ad39849a9ac763ba0e14db5 affected
6829c878ecd24ff0ae41b4668c7e9d0f11b66942< d5e4586546974179feca305a94e07fac3e9727fe affected
2.6.32 affected
< 2.6.32 unaffected
… +6 more rows
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-93805

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
wifi: cfg80211: validate rx/tx MLME callback frame lengths before access
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: wifi: cfg80211: validate rx/tx MLME callback frame lengths before access cfg80211_rx_mlme_mgmt() and cfg80211_tx_mlme_mgmt() call tracepoints before rejecting frames shorter than the frame-control field. After that, they only require len >= 2 before dispatching into subtype handlers that assume their fixed fields are present. The frames that trip this are not shorter than 2 bytes; they are short relative to their subtype. mwifiex is a concrete in-tree example on the length side: mwifiex_process_mgmt_packet() only requires a 4-address ieee80211_hdr plus the 2-byte firmware length prefix before handing the frame to cfg80211_rx_mlme_mgmt(). After stripping the length prefix and removing addr4, pkt_len can be exactly 24: a bare 3-address management header with no reason-code body. The existing WARN_ON(len < 2) does not fire on such a frame, and cfg80211_process_deauth() then reads u.deauth.reason_code as a two-byte access starting at offset 24, immediately past the 24-byte buffer. Add a frame-control length gate, then validate each subtype's minimum frame size in an if/else-if chain that mirrors the dispatch logic. Trace only after the frame is known to be well-formed. Side effects of this change: - The WARN_ON(len < 2) is dropped. It only guarded the frame_control read, never the subtype fixed fields, and it does not fire on the frames that actually trigger the out-of-bounds read (which are >= 2). The len >= 2 check is kept as the guard before dereferencing frame_control, but without the warning: these are exported callbacks and a malformed frame from a driver should be dropped silently rather than backtraced. - cfg80211_tx_mlme_mgmt() previously routed every non-deauth subtype through disassociation handling; it now silently ignores unrecognised subtypes.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Linux Linux 6829c878ecd24ff0ae41b4668c7e9d0f11b66942 ~ 6eb4bd50be53f5afbabb3a3b5153276e08fa7a4a -
Linux Linux 2.6.32 -

II. Public POCs for CVE-2026-93805

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-93805

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-93805 (6)

Same Patch Batch · Linux · 2026-09-24 · 234 CVEs total

CVE-2026-93207 9.8 CRITICAL SUNRPC: Zero rpc_gss_wire_cred at svcauth_gss_decode_credbody() entry
CVE-2026-97413 9.8 CRITICAL RDMA/rtrs-srv: Fix integer underflow in process_read and process_write
CVE-2026-93228 9.1 CRITICAL svcrdma: Reject Write/Reply chunks with segcount 0
CVE-2026-93793 8.8 HIGH wifi: iwlwifi: mvm: validate TX_CMD response layout
CVE-2026-93790 8.8 HIGH wifi: iwlwifi: mvm: fix out-of-bounds tid_data access in BA notif
CVE-2026-93799 8.8 HIGH wifi: iwlwifi: mvm: validate sta_id in BA window status notif
CVE-2026-97442 8.8 HIGH wifi: ath11k: fix invalid data access in ath11k_dp_rx_h_undecap_nwifi
CVE-2026-93806 8.8 HIGH wifi: cfg80211: validate assoc response length before status and IE access
CVE-2026-97509 8.8 HIGH thunderbolt: Keep XDomain reference during the lifetime of a service
CVE-2026-97409 8.8 HIGH nvme-fc: Do not cancel requests in io target before it is initialized
CVE-2026-93280 8.8 HIGH greybus: audio: bound the topology section sizes against the fetched size
CVE-2026-93284 8.8 HIGH drm/pagemap: dma-unmap pages before handling migration errors
CVE-2026-97451 8.4 HIGH ACPICA: Fix integer overflow in acpi_ex_opcode_3A_1T_1R() (mid_op)
CVE-2026-97452 8.4 HIGH ACPICA: Prevent adding invalid references
CVE-2026-97455 8.4 HIGH ACPICA: Fix use-after-free in acpi_ds_terminate_control_method()
CVE-2026-97450 8.4 HIGH ACPICA: validate handler object type in two places
CVE-2026-93827 8.4 HIGH virtio-fs: avoid double-free on failed queue setup
CVE-2026-97433 8.2 HIGH nvme: validate FDP configuration descriptor sizes
CVE-2026-93224 8.1 HIGH svcrdma: Fix unmatched rn_unregister on failed accept
CVE-2026-93787 8.1 HIGH smb: client: bound dirent name against end of SMB response in cifs_filldir

Showing top 20 of 234 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2026-93805

No comments yet


Leave a comment