---
id: CVE-2026-93271
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  wifi: ath11k: cap out-of-range rx MCS instead of leaving bogus rate

  ath11k can receive HT/VHT/HE frames whose reported MCS is above the
  maximum that can be expressed i…
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  wifi: ath11k: cap out-of-range rx MCS instead of leaving bogus rate

  ath11k can receive HT/VHT/HE frames whose reported MCS is above the
  maximum that can be expressed i…
severity: none
vendor: Linux
product: Linux
affected:
  - >-
    Linux >= d5c65159f2895379e11ca13f62feabe93278985d <
    6ad04c3e2ec54bf5ec72c81afdd66318a116c539
  - >-
    Linux >= d5c65159f2895379e11ca13f62feabe93278985d <
    a6b951f79e66fc8bd93a537ff1040fbfb567c8bf
  - >-
    Linux >= d5c65159f2895379e11ca13f62feabe93278985d <
    b77bfe6e59b98dff3ccfcf9b45fc27e3db498626
  - >-
    Linux >= d5c65159f2895379e11ca13f62feabe93278985d <
    fb7b9a7209f839c17c66484dfdc84c9a23c6fd2f
  - >-
    Linux >= d5c65159f2895379e11ca13f62feabe93278985d <
    a0b3e6f9645d88f387c4fea546048a91952cd4cd
  - >-
    Linux >= d5c65159f2895379e11ca13f62feabe93278985d <
    2bb2a778a487305bd378db5fd5014fbdce4ada2c
  - >-
    Linux >= d5c65159f2895379e11ca13f62feabe93278985d <
    ccbd20f2168f581d90265da1a925b9b6472a0b05
  - >-
    Linux >= d5c65159f2895379e11ca13f62feabe93278985d <
    12b09e478aa7459b7893a695ef77682202f2da83
  - Linux 5.6
published: '2026-09-24'
updated: '2026-09-24'
sourceUpdated: '2026-09-24T16:17:24.133'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-93271'
references:
  - url: 'https://git.kernel.org/stable/c/12b09e478aa7459b7893a695ef77682202f2da83'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/2bb2a778a487305bd378db5fd5014fbdce4ada2c'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/6ad04c3e2ec54bf5ec72c81afdd66318a116c539'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/a0b3e6f9645d88f387c4fea546048a91952cd4cd'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/a6b951f79e66fc8bd93a537ff1040fbfb567c8bf'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/b77bfe6e59b98dff3ccfcf9b45fc27e3db498626'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/ccbd20f2168f581d90265da1a925b9b6472a0b05'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/fb7b9a7209f839c17c66484dfdc84c9a23c6fd2f'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-24T16:47:15.839Z'
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

wifi: ath11k: cap out-of-range rx MCS instead of leaving bogus rate

ath11k can receive HT/VHT/HE frames whose reported MCS is above the
maximum that can be expressed in the corresponding mac80211 rate space
(e.g. an HE frame reported with MCS 12, while HE tops out at MCS 11).

The frame itself is valid and decodes correctly, but for such a frame
ath11k_dp_rx_h_rate() leaves rx_status->rate_idx set to the out-of-range
value and never assigns rx_status->encoding, so it stays RX_ENC_LEGACY
from the ath11k_dp_rx_h_ppdu() initialization. Once that frame reaches
mac80211 it trips the rate sanity check and the frame is dropped with a
splat:

  ath11k_pci 0000:03:00.0: Received with invalid mcs in HE mode 12
  WARNING: CPU: 0 PID: 0 at net/mac80211/rx.c:5433 ieee80211_rx_list+0xb0a/0xe90 [mac80211]

Dropping the frame would discard otherwise valid data, so instead cap the
reported MCS to the maximum the rate space can express and deliver the
frame. Set rx_status->encoding before the range check and assign rate_idx
from the capped value, so a frame with an out-of-range MCS no longer
leaves partial or bogus rate metadata behind. Also downgrade the logging
level since they are not treated as invalid frames now. The only loss is
that such a frame is reported as the capped MCS in the rx rate statistics.

Tested-on: WCN6855 hw2.1 PCI WLAN.HSP.1.1-03125-QCAHSPSWPL_V1_V2_SILICONZ_LITE-3.6510.41

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
