---
id: CVE-2026-93064
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  wifi: iwlwifi: mvm: fix off-by-one in TXF key sanitiser

  iwl_mvm_frob_txf_key_iter() tracks the last matched byte position
  in loop variable 'i'
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  wifi: iwlwifi: mvm: fix off-by-one in TXF key sanitiser

  iwl_mvm_frob_txf_key_iter() tracks the last matched byte position
  in loop variable 'i'. When a full key match i…
severity: none
vendor: Linux
product: Linux
affected:
  - >-
    Linux >= 12d60c1efc29e19f4dc0dc70cd48ce097fce6447 <
    1af000d75b1c96f7cbdf23f14d0ee1c51b12f8e6
  - >-
    Linux >= 12d60c1efc29e19f4dc0dc70cd48ce097fce6447 <
    5bcc933c6d47d795dab27458b9001c2d97130fd3
  - >-
    Linux >= 12d60c1efc29e19f4dc0dc70cd48ce097fce6447 <
    4c582ed61325135f841ca93667d7551a8e31e58d
  - >-
    Linux >= 12d60c1efc29e19f4dc0dc70cd48ce097fce6447 <
    c9d8641aea01c3b2516483e128e1f557cfbcf44a
  - >-
    Linux >= 12d60c1efc29e19f4dc0dc70cd48ce097fce6447 <
    2a77cb320e3998afa5e1ed0e95908b226aae9ed6
  - >-
    Linux >= 12d60c1efc29e19f4dc0dc70cd48ce097fce6447 <
    f6a6c01cbc046f68e6916a7e047a1bc881c8c9ab
  - Linux 5.16
published: '2026-09-17'
updated: '2026-09-17'
sourceUpdated: '2026-09-17T17:18:00.150'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-93064'
references:
  - url: 'https://git.kernel.org/stable/c/1af000d75b1c96f7cbdf23f14d0ee1c51b12f8e6'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/2a77cb320e3998afa5e1ed0e95908b226aae9ed6'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/4c582ed61325135f841ca93667d7551a8e31e58d'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/5bcc933c6d47d795dab27458b9001c2d97130fd3'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/c9d8641aea01c3b2516483e128e1f557cfbcf44a'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/f6a6c01cbc046f68e6916a7e047a1bc881c8c9ab'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-17T16:21:47.767Z'
epss: 0.00173
epssPercentile: 0.07
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

wifi: iwlwifi: mvm: fix off-by-one in TXF key sanitiser

iwl_mvm_frob_txf_key_iter() tracks the last matched byte position
in loop variable 'i'. When a full key match is found (match ==
keylen), 'i' points at the last byte of the matched key. The
memset start offset should therefore be i + 1 - keylen, not
i - keylen; the current code zeroes one byte before the match
and leaves the final key byte un-sanitised.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
