Impact
A routine in the rtl8192du driver reads a QoS Traffic Identifier (TID) from an 802.11 header and uses it as an index into an array that only has nine elements. Because the TID is a 4‑bit field, it can range from 0 to 15. Indexing with values 9–15 therefore accesses memory beyond the array bounds. This off‑by‑max error can expose kernel memory contents or overwrite critical data structures, leading to information disclosure, denial of service, or, in the worst case, privilege escalation if control flow is hijacked.
Affected Systems
The flaw resides in the rtl8192du subsystem of the Linux kernel, which is compiled into many Linux distributions to support Realtek RTL8192DU wireless adapters. Any system that loads this module without the vendor’s patch is vulnerable; the CPE indicates the kernel as a whole and the vendor record is simply “Linux:Linux”.
Risk and Exploitability
The CVSS score of 7.6 indicates a high severity, while the EPSS score of <1% shows a very low likelihood of exploitation and it is not present in the CISA KEV catalog. Exploitation requires an attacker to send a crafted 802.11 frame with a QoS TID greater than 8 to a device running the vulnerable driver, implying the attacker must be within physical proximity or have compromised a device on the same wireless network. Successful exploitation would trigger an out‑of‑bounds read or overwrite in kernel space, potentially allowing kernel memory disclosure or corruption.
OpenCVE Enrichment
Debian DSA