CVE-2026-93149

In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211_hwsim: avoid NULL skb in stop queue drain mac80211_hwsim_stop() drops any frames left in data->pending. The loop currently checks skb_queue_empty() and then dequeues separately. That split is racy with TX status handling, which can remove a pending frame under the queue lock. If the last entry is removed after the empty check, skb_dequeue() returns NULL and the stop path passes that NULL skb to ieee80211_free_txskb(). Use skb_dequeue() as the loop condition instead. The dequeue result is the object that stop owns and frees, and a concurrent status completion that empties the queue simply makes the loop terminate.

Package Linux Kernel
Published 2026-09-17
Last modified 2026-09-17
Patch available
Yes

Affected versions

Linux kernel versions 5.4.129, 5.10.47, 5.12.14, 5.13 and later are affected. Fixed in 6.1.188, 6.6.157, 6.12.110, 6.18.52, 7.2.6, 7.3-rc1 and their respective stable series.

Affected from
≥ 5.4.129 ≥ 5.10.47 ≥ 5.12.14 ≥ 5.13
Fixed in
✓ 6.1.188 6.1.x ✓ 6.6.157 6.6.x ✓ 6.12.110 6.12.x ✓ 6.18.52 6.18.x ✓ 7.2.6 7.2.x ✓ 7.3-rc1

Frequently asked questions

  • What is CVE-2026-93149?

    CVE-2026-93149 is a unscored severity Linux kernel vulnerability . It affects Linux kernel versions from 5.4.129 onward and has been patched in 6.1.188, 6.6.157, 6.12.110 and others. CVE-2026-93149 has not been confirmed as actively exploited and is not listed in the CISA KEV catalog.

  • Is there a patch available for CVE-2026-93149?

    Yes. CVE-2026-93149 has been patched. Fixed versions include 6.1.188, 6.6.157, 6.12.110 and others. If you are running Linux kernel 5.4.129 or later up to the fix versions, apply the relevant patch for your kernel branch.

  • Is CVE-2026-93149 actively exploited?

    No. CVE-2026-93149 has not been confirmed as actively exploited. It is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.