Description
In the Linux kernel, the following vulnerability has been resolved:

wifi: iwlwifi: mei: check SAP message length before reading it

Verify the SAP message size is not larger than the local buffer before
reading the message to avoid buffer overflow.
Published: 2026-09-17
Score: 8.4 High
EPSS: < 1% Very Low
KEV: No
Impact: Potential Remote Code Execution
Action: Apply Patch
AI Analysis

Impact

The Linux kernel wireless driver iwlwifi contained a flaw that does not verify the length of a Service Access Point (SAP) message before copying it into a local buffer. An attacker that can inject an oversized SAP message will cause the kernel copy operation to overflow the buffer, allowing the attacker to overwrite adjacent kernel memory. Depending on the memory layout, this overflow could be used to execute arbitrary code, elevate privileges, or crash the kernel, resulting in a denial‑of‑service. The CVSS score of 8.4 indicates that code execution is a realistic outcome.

Affected Systems

All Linux systems running a kernel that contains the iwlwifi driver and the MEI interface, regardless of distribution, are potentially affected. No explicit version ranges were provided, but any kernel revision prior to the patch that added the SAP message length check is vulnerable.

Risk and Exploitability

With a CVSS score of 8.4 the vulnerability is high severity. The EPSS score of less than 1% indicates that, at the time of analysis, the probability of a publicly available exploit is very low. The vulnerability is not listed in the CISA KEV catalog, so it is not known to be actively exploited in the wild. The likely attack vector involves an attacker sending crafted SAP messages over the wireless interface to the target device, which requires the device to be in a state where the iwlwifi driver processes these messages. Local exploitation is possible, and if the attacker gains higher privileges, remote code execution across the host can be achieved.

Generated by OpenCVE AI on September 19, 2026 at 22:28 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Linux kernel to the latest version that includes the check for SAP message length, ensuring the buffer overflow is fixed.
  • If an immediate kernel update is not available, disable or unload the iwlwifi driver or disable the MEI interface to eliminate the vulnerable code path.
  • Monitor kernel logs and system stability for indicators of memory corruption or crashes, and apply additional kernel hardening options such as CONFIG_RANDOMIZE_MEMORY and CONFIG_KMALLOC_RECLAIM.

Generated by OpenCVE AI on September 19, 2026 at 22:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sat, 19 Sep 2026 23:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-787

Sat, 19 Sep 2026 17:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-122

Sat, 19 Sep 2026 07:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-122

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.4, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: mei: check SAP message length before reading it Verify the SAP message size is not larger than the local buffer before reading the message to avoid buffer overflow.
Title wifi: iwlwifi: mei: check SAP message length before reading it
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-18T17:55:49.739Z

Reserved: 2026-09-17T15:57:05.660Z

Link: CVE-2026-93063

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:18:00.013

Modified: 2026-09-18T18:18:19.777

Link: CVE-2026-93063

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T22:45:06Z

Weaknesses