unknown
CVE-2026-93802
In the Linux kernel, the following vulnerability has been resolved: wifi: rsi: validate beacon length before fixed buffe…
Description
In the Linux kernel, the following vulnerability has been resolved: wifi: rsi: validate beacon length before fixed buffer copy rsi_prepare_beacon() copies the mac80211 beacon frame after FRAME_DESC_SZ into a management skb whose usable tailroom may be smaller than MAX_MGMT_PKT_SIZE after alignment. Validate the beacon length against the actual tailroom before the copy and skb_put(). Leave ownership of the management skb with the caller on error, matching the existing rsi_send_beacon() cleanup path.
Scores
- Severity
- unknown
- CVSS v2
- —
- CVSS v3
- —
- CVSS v4
- —
- EPSS
- —