Description
In the Linux kernel, the following vulnerability has been resolved:

wifi: iwlwifi: fix counter type in iwl_fwrt_dump_error_logs

The loop counter 'count' was declared as u8 while num_pc is u32.
If firmware advertises more than 255 PC entries the counter wraps
back to zero and the loop never terminates potentially causing an
infinite loop or reading past the allocated pc_data array.

Change the declaration to u32 to match num_pc.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service (Kernel Hang)
Action: Apply Update
AI Analysis

Impact

The iwlwifi driver in the Linux kernel uses a loop counter declared as an 8‑bit unsigned integer while the firmware reports the number of program counter entries as a 32‑bit value. When the firmware advertises more than 255 entries, the counter wraps to zero and the loop never terminates, potentially leading to an infinite loop or an out‑of‑bounds read in kernel space. This can cause a kernel panic or a system hang, effectively denying service to the operating system.

Affected Systems

Any Linux system that ships with an iwlwifi driver containing the pre‑fix code is affected. The commit that corrects the counter type was merged into the mainline kernel and is included in recent distribution kernels. Systems running kernel releases older than that commit, or with a custom build that has not applied the change, remain vulnerable. No specific kernel version range was supplied in the CVE data, so the default assessment is that all unpatched kernels are at risk until the fix is applied.

Risk and Exploitability

The EPSS score indicates a less than 1 % chance of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Based on the description it is inferred that an attacker would need to trigger the iwlwifi firmware logs that contain an oversized list of program counter entries, which requires either local access or a malicious firmware package supplied by the wireless hardware. No public exploit has been documented, so the overall risk is moderate, but the potential impact merits timely patching to eliminate the possibility of a kernel hang.

Generated by OpenCVE AI on September 19, 2026 at 12:29 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Install the latest kernel version from your distribution that incorporates the iwlwifi counter‑type fix.
  • If a patched kernel is not yet available, unload or blacklist the iwlwifi module (e.g., with `modprobe -r iwlwifi` or adding it to the blacklist configuration) to avoid the problematic code path.
  • Continuously monitor system logs for kernel panics or out‑of‑bounds read warnings that could indicate an attempted exploitation, and apply firmware updates from Intel that constrain the number of program counter entries if such updates become available.

Generated by OpenCVE AI on September 19, 2026 at 12:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sat, 19 Sep 2026 12:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-190
CWE-788

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: fix counter type in iwl_fwrt_dump_error_logs The loop counter 'count' was declared as u8 while num_pc is u32. If firmware advertises more than 255 PC entries the counter wraps back to zero and the loop never terminates potentially causing an infinite loop or reading past the allocated pc_data array. Change the declaration to u32 to match num_pc.
Title wifi: iwlwifi: fix counter type in iwl_fwrt_dump_error_logs
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:10:50.940Z

Reserved: 2026-09-17T15:57:05.660Z

Link: CVE-2026-93065

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:18:00.267

Modified: 2026-09-17T17:18:00.267

Link: CVE-2026-93065

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T14:00:14Z

Weaknesses
  • CWE-190

    Integer Overflow or Wraparound

  • CWE-788

    Access of Memory Location After End of Buffer