Out-of-Range MCS Vulnerability in ath11k Wireless Driver by Linux Kernel
CVE-2026-93271

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
24 September 2026

What is CVE-2026-93271?

The ath11k wireless driver in the Linux kernel was found to handle incoming HT/VHT/HE frames with an invalid MCS (Modulation and Coding Scheme) value incorrectly. Specifically, when the reported MCS exceeded the limit for the associated mac80211 rate space, the driver failed to properly assign rate status. This incorrectly flagged otherwise valid frames, leading to loss of data due to frame rejection by the rate sanity check. This defect has been addressed to ensure that valid frames are not dropped and that the reported MCS is capped to the communicative constraints of the established protocol, thereby enhancing the overall reliability of wireless communications.

Affected Version(s)

Linux d5c65159f2895379e11ca13f62feabe93278985d < 6ad04c3e2ec54bf5ec72c81afdd66318a116c539

Linux d5c65159f2895379e11ca13f62feabe93278985d

Linux d5c65159f2895379e11ca13f62feabe93278985d

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.