Impact
The Linux kernel rtw88 PCI driver contains a flaw where the probe routine allocates PCI resources before initializing NAPI. If the NAPI setup fails, the error path jumps directly to error handling without calling the routine that normally releases the resources. As a result, the previously allocated PCI resources remain reserved, creating a leak. Over time, repeated failures can deplete the limited pool of PCI addresses and interrupts, disrupting normal driver operation and potentially cascading into broader system instability.
Affected Systems
All Linux kernel releases that include the rtw88 Wi‑Fi driver version that lacks the fix are affected. The issue is present at least from mainline kernel 7.1‑rc7 and earlier; it remains in any kernel that builds the legacy rtw88 driver for PCI Wi‑Fi adapters without the patch. Systems that load the rtw88 module and use a PCI Wi‑Fi device are susceptible; those that never load the driver or only use other Wi‑Fi drivers are not impacted.
Risk and Exploitability
The CVSS score of 4.1 indicates moderate severity. The EPSS score is less than 1 %, and the vulnerability is not listed in the CISA KEV catalog, suggesting low exploitation probability and no known exploits. The primary attack vector is local: a privileged user or kernel process that can trigger the probe routine, such as boot time or hot‑plug events, can induce repeated NAPI failures and cause the resource leak. Because the flaw does not provide code execution or privilege escalation, the impact is limited to resource exhaustion and likely denial of service of Wi‑Fi functionality or system instability.
OpenCVE Enrichment
Debian DSA