Description
In the Linux kernel, the following vulnerability has been resolved:

wifi: rtw88: fix wrong pci_get_drvdata type in AER handlers

rtw88 stores an ieee80211_hw pointer via pci_set_drvdata() at probe
time, but io_error_detected() and io_resume() retrieve it as a
net_device pointer. This causes netif_device_detach/attach to
operate on an ieee80211_hw struct, reading and writing at wrong
offsets.

Use ieee80211_stop_queues/wake_queues instead, consistent with
every other queue stop/start path in the driver.
Published: 2026-08-15
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The rtw88 wireless driver stores an ieee80211_hw pointer using pci_set_drvdata() during probe, but later attempts to retrieve it as a net_device pointer in the AER handlers. This type mismatch causes netif_device_detach/attach to operate on the wrong structure, corrupting memory and leading to a kernel crash. The crash renders the Wi‑Fi stack unusable and can bring the entire system down, resulting in a denial‑of‑service. The flaw demonstrates type confusion (CWE‑843).

Affected Systems

The vulnerability is present in any Linux kernel that includes the rtw88 driver before the industrial patch is applied. All distributions shipping a kernel with this driver are potentially impacted. No specific vendor or version list is supplied beyond the generic Linux kernel CPE, meaning every kernel that loads rtw88 could be affected.

Risk and Exploitability

The CVSS score of 8.8 reflects a high severity to system stability. The EPSS score of < 1% indicates a very low likelihood of exploitation under normal circumstances. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires an environment that triggers the AER error paths, which typically arise from hardware faults, making it a local, privilege‑related risk. Overall risk is moderate to high for impacted systems that cannot apply the patch in a timely manner.

Generated by OpenCVE AI on August 22, 2026 at 02:34 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor‑supplied kernel patch that corrects the pci_get_drvdata type mismatch and replaces netif_device_detach/attach with ieee80211_stop_queues/wake_queues—this fixes the type confusion (CWE‑843) and associated memory corruption.
  • Upgrade to a kernel release that includes the rtw88 driver fix; the new kernel contains the corrected driver code that resolves the type mismatch and prevents the crash.
  • If an immediate kernel upgrade is not feasible, temporarily unload or disable the rtw88 module to avoid triggering the erroneous AER handlers until the patch or newer kernel is installed, mitigating the out‑of‑bounds write.

Generated by OpenCVE AI on August 22, 2026 at 02:34 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 22 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-704
CWE-787

Fri, 21 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-843
References
Metrics threat_severity

None

threat_severity

Moderate


Mon, 17 Aug 2026 14:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-704
CWE-787

Mon, 17 Aug 2026 12:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-119
CWE-676

Mon, 17 Aug 2026 06:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Sat, 15 Aug 2026 14:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-119
CWE-676

Sat, 15 Aug 2026 06:15:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: wifi: rtw88: fix wrong pci_get_drvdata type in AER handlers rtw88 stores an ieee80211_hw pointer via pci_set_drvdata() at probe time, but io_error_detected() and io_resume() retrieve it as a net_device pointer. This causes netif_device_detach/attach to operate on an ieee80211_hw struct, reading and writing at wrong offsets. Use ieee80211_stop_queues/wake_queues instead, consistent with every other queue stop/start path in the driver.
Title wifi: rtw88: fix wrong pci_get_drvdata type in AER handlers
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-08-17T05:46:55.998Z

Reserved: 2026-08-15T05:44:03.893Z

Link: CVE-2026-74412

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-15T06:22:43.317

Modified: 2026-08-17T06:19:36.680

Link: CVE-2026-74412

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-08-15T00:00:00Z

Links: CVE-2026-74412 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-22T02:45:03Z

Weaknesses
  • CWE-843

    Access of Resource Using Incompatible Type ('Type Confusion')