GHSA-cv3p-w443-82hjHighCVSS 8.8

In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: mvm: validate...

Published
September 24, 2026
Last Modified
September 25, 2026

🔗 CVE IDs covered (1)

📋 Description

In the Linux kernel, the following vulnerability has been resolved:

wifi: iwlwifi: mvm: validate TX_CMD response layout

TX_CMD parsing uses frame_count to walk status entries and then read the trailing SCD SSN. Make the minimum-length check follow that exact runtime layout calculation before parsing the payload.

For new TX API, reject TX_CMD responses with frame_count != 1 and warn/return in the aggregation handler to document that aggregated accounting is expected via BA notifications.

🔗 References (5)