Description
In the Linux kernel, the following vulnerability has been resolved:

wifi: rtw89: pci: validate release report content before using for RTL8922DE

The commit 957eda596c76
("wifi: rtw89: pci: validate sequence number of TX release report")
does validation on existing chips, which somehow a release report of SKB
becomes malformed. As no clear cause found, add rules ahead for RTL8922DE
to avoid crash if it happens.
Published: 2026-05-06
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Linux kernel driver for rtw89 Wi‑Fi hardware has insufficient validation of release report contents for the RTL8922DE model, a flaw identified as a validation failure (CWE-1286); no other CWE identifiers are known, as indicated by the NVD-CWE-noinfo entry. When a malformed report is processed, the driver may access the data incorrectly and trigger a kernel panic, resulting in a system crash and denial of service.

Affected Systems

All Linux kernel installations that include the unpatched rtw89 driver and incorporate RTL8922DE Wi‑Fi hardware are affected. The vulnerability applies to any system where the PCI rtw89 driver is loaded for this device, regardless of distribution or kernel version prior to the inclusion of commit 957eda596c76.

Risk and Exploitability

The CVSS score of 8.8 indicates a medium‑to‑high risk, primarily due to the potential for a kernel crash. The EPSS score is 0.00019 and the issue is not listed in the KEV catalog. The description notes that a malformed release report can trigger a kernel panic, but the public data does not detail the exact prerequisites for an attacker to produce such a report. No remote exploitation or privilege escalation is documented in the provided data.

Generated by OpenCVE AI on May 12, 2026 at 22:48 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Linux kernel to a version that includes commit 957eda596c76, which introduces proper validation for RTL8922DE release reports.
  • If a kernel upgrade is not possible, disable or unload the rtw89 PCI module or block the device via firmware or module parameters to prevent interaction with the vulnerable code.
  • Continuously monitor kernel logs for crash indications (e.g., dmesg or /var/log/kern.log) and apply subsequent kernel updates as they become available.

Generated by OpenCVE AI on May 12, 2026 at 22:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 12 May 2026 20:15:00 +0000

Type Values Removed Values Added
Weaknesses NVD-CWE-noinfo

Fri, 08 May 2026 13:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.0, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'}

cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Thu, 07 May 2026 04:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-295

Thu, 07 May 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-1286
References
Metrics threat_severity

None

cvssV3_1

{'score': 7.0, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'}

threat_severity

Moderate


Wed, 06 May 2026 16:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-295

Wed, 06 May 2026 12:15:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: wifi: rtw89: pci: validate release report content before using for RTL8922DE The commit 957eda596c76 ("wifi: rtw89: pci: validate sequence number of TX release report") does validation on existing chips, which somehow a release report of SKB becomes malformed. As no clear cause found, add rules ahead for RTL8922DE to avoid crash if it happens.
Title wifi: rtw89: pci: validate release report content before using for RTL8922DE
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-05-11T22:19:15.630Z

Reserved: 2026-05-01T14:12:55.991Z

Link: CVE-2026-43176

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2026-05-06T12:16:36.083

Modified: 2026-05-12T20:01:03.450

Link: CVE-2026-43176

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-05-06T00:00:00Z

Links: CVE-2026-43176 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-05-12T23:00:12Z