Description
In the Linux kernel, the following vulnerability has been resolved:

wifi: iwlwifi: mvm: fix off-by-one in TXF key sanitiser

iwl_mvm_frob_txf_key_iter() tracks the last matched byte position
in loop variable 'i'. When a full key match is found (match ==
keylen), 'i' points at the last byte of the matched key. The
memset start offset should therefore be i + 1 - keylen, not
i - keylen; the current code zeroes one byte before the match
and leaves the final key byte un-sanitised.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Potential Information Disclosure via Unsanitised Wireless Key Byte
Action: Apply Patch
AI Analysis

Impact

The vulnerability in the Linux kernel’s iwlwifi driver allows the last byte of a Wi‑Fi key to remain unsanitised during memory cleanup. This off‑by‑one error means that one byte of a key may remain in memory, potentially enabling a local attacker to read a part of the key and compromise the confidentiality of wireless traffic. The impact is limited to a single key byte but could be compounded if several keys are affected or if keys are long enough to provide sufficient material for cryptanalysis.

Affected Systems

All Linux systems that use the iwlwifi driver in the kernel, regardless of distribution. The affected code path is part of the kernel’s wireless interface module for Intel wireless devices. Specific kernel versions are not listed; any version prior to the patch should be considered vulnerable.

Risk and Exploitability

The EPSS score is below 1 % and the vulnerability is not included in CISA’s KEV catalog, indicating a low probability of successful exploitation. However, the CWEs associated with buffer calculation errors and information disclosure suggest that if an attacker gains local kernel execution or can observe memory, a single key byte could be recovered. The risk is therefore moderate: significant but difficult to exploit, and mitigated by updating to a kernel version where the bug is fixed.

Generated by OpenCVE AI on September 19, 2026 at 09:16 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Linux kernel to a version that includes the fix for the key sanitisation off‑by‑one error
  • Use kernel live patching (e.g., kpatch or kgraft) to apply the fix without rebooting if an immediate upgrade is not feasible
  • If live patching is unavailable, disable the iwlwifi driver or switch to a different wireless interface to reduce exposure

Generated by OpenCVE AI on September 19, 2026 at 09:16 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sat, 19 Sep 2026 09:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-131
CWE-200

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: mvm: fix off-by-one in TXF key sanitiser iwl_mvm_frob_txf_key_iter() tracks the last matched byte position in loop variable 'i'. When a full key match is found (match == keylen), 'i' points at the last byte of the matched key. The memset start offset should therefore be i + 1 - keylen, not i - keylen; the current code zeroes one byte before the match and leaves the final key byte un-sanitised.
Title wifi: iwlwifi: mvm: fix off-by-one in TXF key sanitiser
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:10:50.254Z

Reserved: 2026-09-17T15:57:05.660Z

Link: CVE-2026-93064

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:18:00.150

Modified: 2026-09-17T17:18:00.150

Link: CVE-2026-93064

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T17:15:04Z

Weaknesses
  • CWE-131

    Incorrect Calculation of Buffer Size

  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor