CVE-2026-93802

In the Linux kernel, the following vulnerability has been resolved: wifi: rsi: validate beacon length before fixed buffer copy rsi_prepare_beacon() copies the mac80211 beacon frame after FRAME_DESC_SZ into a management skb whose usable tailroom may be smaller than MAX_MGMT_PKT_SIZE after alignment. Validate the beacon length against the actual tailroom before the copy and skb_put(). Leave ownership of the management skb with the caller on error, matching the existing rsi_send_beacon() cleanup path.

Package Linux Kernel
Published 2026-09-24
Last modified 2026-10-03
Patch available
Yes

Affected versions

Linux kernel versions 4.14 and later are affected. Fixed in 5.10.271, 5.15.222, 6.1.189, 6.6.158, 6.12.111, 6.18.53, 7.2 and their respective stable series.

Affected from
≥ 4.14
Fixed in
✓ 5.10.271 5.10.x ✓ 5.15.222 5.15.x ✓ 6.1.189 6.1.x ✓ 6.6.158 6.6.x ✓ 6.12.111 6.12.x ✓ 6.18.53 6.18.x ✓ 7.2

Frequently asked questions

  • What is CVE-2026-93802?

    CVE-2026-93802 is a unscored severity Linux kernel vulnerability . It affects Linux kernel versions from 4.14 onward and has been patched in 5.10.271, 5.15.222, 6.1.189 and others. CVE-2026-93802 has not been confirmed as actively exploited and is not listed in the CISA KEV catalog.

  • Is there a patch available for CVE-2026-93802?

    Yes. CVE-2026-93802 has been patched. Fixed versions include 5.10.271, 5.15.222, 6.1.189 and others. If you are running Linux kernel 4.14 or later up to the fix versions, apply the relevant patch for your kernel branch.

  • Is CVE-2026-93802 actively exploited?

    No. CVE-2026-93802 has not been confirmed as actively exploited. It is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.