CVE-2026-93149
Received
Received - Intake
BaseFortify
Vulnerability report for CVE-2026-93149, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-09-17
Last updated on: 2026-09-17
Assigner: kernel.org
Description
Description
In the Linux kernel, the following vulnerability has been resolved:
wifi: mac80211_hwsim: avoid NULL skb in stop queue drain
mac80211_hwsim_stop() drops any frames left in data->pending. The loop
currently checks skb_queue_empty() and then dequeues separately.
That split is racy with TX status handling, which can remove a pending
frame under the queue lock. If the last entry is removed after the empty
check, skb_dequeue() returns NULL and the stop path passes that NULL skb
to ieee80211_free_txskb().
Use skb_dequeue() as the loop condition instead. The dequeue result is the
object that stop owns and frees, and a concurrent status completion that
empties the queue simply makes the loop terminate.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| Linux | Linux | bd18de517923903a177508fc8813f44e717b1c00 |
| Linux | Linux | bd18de517923903a177508fc8813f44e717b1c00 |
| Linux | Linux | bd18de517923903a177508fc8813f44e717b1c00 |
| Linux | Linux | bd18de517923903a177508fc8813f44e717b1c00 |
| Linux | Linux | bd18de517923903a177508fc8813f44e717b1c00 |
| Linux | Linux | bd18de517923903a177508fc8813f44e717b1c00 |
| Linux | Linux | 78bf3c6131488b00386acd9aff1ea4e6c44fa38e |
| Linux | Linux | a9028333001f793b2724e8be42fce3336de2cf1c |
| Linux | Linux | 7019c9f385b264a2d6f685028268422d55087e37 |
| Linux | Linux | 5.4.129 |
| Linux | Linux | 5.10.47 |
| Linux | Linux | 5.12.14 |
| Linux | Linux | 5.13 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-UNKNOWN |