Description
In the Linux kernel, the following vulnerability has been resolved:

wifi: iwlwifi: fix 22000 series SMEM parsing

If the firmware were to report three LMACs (which doesn't
exist in hardware) then using "fwrt->smem_cfg.lmac[2]" is
an overrun of the array. Reject such and use IWL_FW_CHECK
instead of WARN_ON in this function.
Published: 2026-05-06
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The iwlwifi driver contains an out‑of‑bounds array access that occurs when firmware reports three legacy MAC (LMAC) interfaces, a configuration that hardware never supports. The code incorrectly indexes fwrt->smem_cfg.lmac[2], causing a memory overrun that can corrupt adjacent kernel data. The vulnerability does not disclose a guaranteed remote execution path, but it may compromise system stability and provide an attacker with the potential to exploit kernel memory corruption.

Affected Systems

Any Linux system using the Intel 22000 series wireless driver (iwlwifi) before the SMEM parsing fix was applied is affected. The CPE indicates all Linux kernel versions; specific vulnerable releases are not enumerated in the data, so the exposure applies to pre‑patch kernels that contain the buggy driver code.

Risk and Exploitability

The CVSS score of 8.8 reflects high severity, yet the EPSS score of less than 1% signals a low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that an attacker would need to influence the firmware data read by the driver, for example by supplying custom firmware. The likely attack vector is that an attacker could manipulate custom firmware loaded by the system, though this scenario is not typically viable in standard consumer deployments with signed OEM firmware. Overall, the risk is moderate for environments that load firmware from untrusted sources and low for standard consumer installations.

Generated by OpenCVE AI on May 13, 2026 at 18:14 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Linux kernel to a release that incorporates the iwlwifi SMEM parsing fix as referenced by the kernel commit logs.
  • Apply vendor or distribution security updates that include the iwlwifi driver patch.
  • Confirm that firmware loading mechanisms enforce the IWL_FW_CHECK validation to reject firmware reporting an invalid LMAC count.

Generated by OpenCVE AI on May 13, 2026 at 18:14 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 13 May 2026 15:30:00 +0000

Type Values Removed Values Added
Weaknesses NVD-CWE-noinfo

Fri, 08 May 2026 13:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.0, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'}

cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Thu, 07 May 2026 04:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-119

Thu, 07 May 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-1285
References
Metrics threat_severity

None

cvssV3_1

{'score': 7.0, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'}

threat_severity

Moderate


Wed, 06 May 2026 16:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-119

Wed, 06 May 2026 12:15:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: fix 22000 series SMEM parsing If the firmware were to report three LMACs (which doesn't exist in hardware) then using "fwrt->smem_cfg.lmac[2]" is an overrun of the array. Reject such and use IWL_FW_CHECK instead of WARN_ON in this function.
Title wifi: iwlwifi: fix 22000 series SMEM parsing
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-05-11T22:19:10.785Z

Reserved: 2026-05-01T14:12:55.991Z

Link: CVE-2026-43172

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2026-05-06T12:16:35.583

Modified: 2026-05-13T14:56:38.797

Link: CVE-2026-43172

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-05-06T00:00:00Z

Links: CVE-2026-43172 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-05-13T18:15:16Z