Description
In the Linux kernel, the following vulnerability has been resolved:

wifi: iwlwifi: guard against division by zero in iwl_dbg_tlv_alloc_fragments

Make sure we don't end-up with a num_frags = 0 situation.
For that, check that the required size is not 0 and put a checker on
num_frags as well.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Patch
AI Analysis

Impact

The bug resides in the iwlwifi driver of the Linux kernel, where a calculation that allocates fragments for debug TLV structures can produce a divisor of zero. The resulting division-by-zero fault can trigger a kernel panic, causing the operating system to crash and forcing a reboot. This manifests as a denial‑of‑service condition that affects system availability, but does not compromise confidentiality or integrity, and is limited to systems that load the unpatched iwlwifi module.

Affected Systems

All Linux kernel implementations that include the unmodified iwlwifi driver are potentially impacted. The advisory does not enumerate specific kernel versions, so any kernel build lacking the divisor‑zero guard is considered at risk.

Risk and Exploitability

The EPSS score of less than 1 % indicates a very low probability of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires invoking the specific debug path that calls iwl_dbg_tlv_alloc_fragments, which typically demands local privileged access or a scenario where an attacker can influence the size of a debug message. Given these constraints, the overall risk is moderate, though a successful crash would have high impact.

Generated by OpenCVE AI on September 19, 2026 at 09:16 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply a Linux kernel update that contains the iwlwifi division‑by‑zero fix.
  • If an immediate kernel upgrade is not possible, disable or limit iwlwifi debug logging by setting the module parameter that controls TLV debugging, or by adjusting the appropriate sysctl value.
  • Verify that no malformed debug inputs can reach the iwl_dbg_tlv_alloc_fragments routine, ensuring the mitigations remain effective.

Generated by OpenCVE AI on September 19, 2026 at 09:16 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sat, 19 Sep 2026 09:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-199
CWE-368

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: guard against division by zero in iwl_dbg_tlv_alloc_fragments Make sure we don't end-up with a num_frags = 0 situation. For that, check that the required size is not 0 and put a checker on num_frags as well.
Title wifi: iwlwifi: guard against division by zero in iwl_dbg_tlv_alloc_fragments
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:10:48.451Z

Reserved: 2026-09-17T15:57:05.660Z

Link: CVE-2026-93062

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:59.897

Modified: 2026-09-17T17:17:59.897

Link: CVE-2026-93062

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T20:00:13Z

Weaknesses