CVE-2026-93149
In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211_hwsim: avoid NULL skb in stop queue drain mac80211_hwsim_stop() drops any frames left in data->pending. The loop currently checks skb_queue_empty() and then dequeues separately. That split is racy with TX status handling, which can remove a pending frame under the queue lock. If the last entry is removed after the empty check, skb_dequeue() returns NULL and the stop path passes that NULL skb to ieee80211_free_txskb(). Use skb_dequeue() as the loop condition instead. The dequeue result is the object that stop owns and frees, and a concurrent status completion that empties the queue simply makes the loop terminate.
Affected versions
Linux kernel versions
5.4.129,
5.10.47,
5.12.14,
5.13
and later are affected. Fixed in
6.1.188,
6.6.157,
6.12.110,
6.18.52,
7.2.6,
7.3-rc1
and their respective stable series.
References
6 totalFrequently asked questions
-
What is CVE-2026-93149?
CVE-2026-93149 is a unscored severity Linux kernel vulnerability . It affects Linux kernel versions from 5.4.129 onward and has been patched in 6.1.188, 6.6.157, 6.12.110 and others. CVE-2026-93149 has not been confirmed as actively exploited and is not listed in the CISA KEV catalog.
-
Is there a patch available for CVE-2026-93149?
Yes. CVE-2026-93149 has been patched. Fixed versions include 6.1.188, 6.6.157, 6.12.110 and others. If you are running Linux kernel 5.4.129 or later up to the fix versions, apply the relevant patch for your kernel branch.
-
Is CVE-2026-93149 actively exploited?
No. CVE-2026-93149 has not been confirmed as actively exploited. It is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.