Description
In the Linux kernel, the following vulnerability has been resolved:

wifi: rtlwifi: rtl8192du: check QoS TID before indexing tids

rtl92du_tx_fill_desc() uses ieee80211_get_tid() to read the QoS TID
from the 802.11 header and then uses it as an index into
sta_entry->tids[]. ieee80211_get_tid() returns the low 4-bit QoS TID
value, so the result can be in the range 0..15.

rtlwifi only allocates MAX_TID_COUNT entries for sta_entry->tids[], and
MAX_TID_COUNT is 9. A QoS TID greater than 8 therefore indexes past the
aggregation state array. Keep the default RTL_AGG_STOP state for
out-of-range TIDs, matching rtl92cu_tx_fill_desc().

This issue was detected by our static analysis tool and confirmed by
manual audit. UBSAN validation for the same bug pattern reports an
array-index-out-of-bounds access with index 10 for type
'rtl_tid_data [9]'.
Published: 2026-09-11
Score: 7.6 High
EPSS: < 1% Very Low
KEV: No
Impact: Out-of-bounds array index in Wi‑Fi driver potentially exposing kernel memory
Action: Patch Kernel
AI Analysis

Impact

A routine in the rtl8192du driver reads a QoS Traffic Identifier (TID) from an 802.11 header and uses it as an index into an array that only has nine elements. Because the TID is a 4‑bit field, it can range from 0 to 15. Indexing with values 9–15 therefore accesses memory beyond the array bounds. This off‑by‑max error can expose kernel memory contents or overwrite critical data structures, leading to information disclosure, denial of service, or, in the worst case, privilege escalation if control flow is hijacked.

Affected Systems

The flaw resides in the rtl8192du subsystem of the Linux kernel, which is compiled into many Linux distributions to support Realtek RTL8192DU wireless adapters. Any system that loads this module without the vendor’s patch is vulnerable; the CPE indicates the kernel as a whole and the vendor record is simply “Linux:Linux”.

Risk and Exploitability

The CVSS score of 7.6 indicates a high severity, while the EPSS score of <1% shows a very low likelihood of exploitation and it is not present in the CISA KEV catalog. Exploitation requires an attacker to send a crafted 802.11 frame with a QoS TID greater than 8 to a device running the vulnerable driver, implying the attacker must be within physical proximity or have compromised a device on the same wireless network. Successful exploitation would trigger an out‑of‑bounds read or overwrite in kernel space, potentially allowing kernel memory disclosure or corruption.

Generated by OpenCVE AI on September 21, 2026 at 02:55 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest Linux kernel version that includes the rtl8192du QoS TID bounds‑check patch.
  • If an upgrade is not feasible, unload or disable the rtl8192du driver or switch to a non‑vulnerable Wi‑Fi interface.
  • Configure access‑point or firewall rules to drop 802.11 frames with QoS TID values exceeding 8, reducing the attack surface.

Generated by OpenCVE AI on September 21, 2026 at 02:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sun, 13 Sep 2026 06:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H'}

cvssV3_1

{'score': 7.6, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H'}


Sat, 12 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-787
References
Metrics threat_severity

None

cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H'}

threat_severity

Important


Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: wifi: rtlwifi: rtl8192du: check QoS TID before indexing tids rtl92du_tx_fill_desc() uses ieee80211_get_tid() to read the QoS TID from the 802.11 header and then uses it as an index into sta_entry->tids[]. ieee80211_get_tid() returns the low 4-bit QoS TID value, so the result can be in the range 0..15. rtlwifi only allocates MAX_TID_COUNT entries for sta_entry->tids[], and MAX_TID_COUNT is 9. A QoS TID greater than 8 therefore indexes past the aggregation state array. Keep the default RTL_AGG_STOP state for out-of-range TIDs, matching rtl92cu_tx_fill_desc(). This issue was detected by our static analysis tool and confirmed by manual audit. UBSAN validation for the same bug pattern reports an array-index-out-of-bounds access with index 10 for type 'rtl_tid_data [9]'.
Title wifi: rtlwifi: rtl8192du: check QoS TID before indexing tids
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-13T06:28:18.870Z

Reserved: 2026-08-26T14:34:25.803Z

Link: CVE-2026-80943

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:18:59.807

Modified: 2026-09-13T07:17:01.543

Link: CVE-2026-80943

cve-icon Redhat

Severity : Important

Publid Date: 2026-09-11T19:42:15Z

Links: CVE-2026-80943 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T03:00:12Z

Weaknesses