PT-2026-97996 · Linux · Linux Kernel

CVE-2026-93796

·

Published

2026-09-24

·

Updated

2026-09-25

CVSS v3.1

7.0

High

VectorAV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description An issue exists in the iwlwifi driver within the PCIe component where RX pointers remain non-NULL after being freed. When the iwl pcie tx init() function fails following RX initialization, the network interface card initialization is undone via iwl pcie rx free(). Because the freed RX members are not reset to NULL on the live transport object, subsequent teardown or retry attempts may access stale RX state. This involves the rx pool, global table, rxq, and alloc page variables.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-93796

Affected Products

Linux Kernel