Impact
The Linux kernel driver for rtw89 Wi‑Fi hardware has insufficient validation of release report contents for the RTL8922DE model, a flaw identified as a validation failure (CWE-1286); no other CWE identifiers are known, as indicated by the NVD-CWE-noinfo entry. When a malformed report is processed, the driver may access the data incorrectly and trigger a kernel panic, resulting in a system crash and denial of service.
Affected Systems
All Linux kernel installations that include the unpatched rtw89 driver and incorporate RTL8922DE Wi‑Fi hardware are affected. The vulnerability applies to any system where the PCI rtw89 driver is loaded for this device, regardless of distribution or kernel version prior to the inclusion of commit 957eda596c76.
Risk and Exploitability
The CVSS score of 8.8 indicates a medium‑to‑high risk, primarily due to the potential for a kernel crash. The EPSS score is 0.00019 and the issue is not listed in the KEV catalog. The description notes that a malformed release report can trigger a kernel panic, but the public data does not detail the exact prerequisites for an attacker to produce such a report. No remote exploitation or privilege escalation is documented in the provided data.
OpenCVE Enrichment