PT-2026-104848 · Azure Linux · Kernel
Published
2026-09-24
·
Updated
2026-09-24
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
wifi: iwlwifi: mvm: validate TX CMD response layout
TX CMD parsing uses frame count to walk status entries and then
read the trailing SCD SSN. Make the minimum-length check follow
that exact runtime layout calculation before parsing the payload.
For new TX API, reject TX CMD responses with frame count != 1 and
warn/return in the aggregation handler to document that aggregated
accounting is expected via BA notifications.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Kernel