Description
In the Linux kernel, the following vulnerability has been resolved:

wifi: rtlwifi: pci: fix error path in rtl_pci_probe()

In the last error path in rtl_pci_probe(), the cleanup functions are
skipped due to a wrong goto label. Moreover, the successful call to
rtl_init_rfkill(), ieee80211_register_hw(), rtl_debug_add_one() have to
be reverted. Fix this issue by updating the labels and adding the
relevant cleanup functions to the last error path.
Published: 2026-09-17
Score: 7 High
EPSS: < 1% Very Low
KEV: No
Impact: Kernel Resource Leak
Action: Apply Patch
AI Analysis

Impact

The rtlwifi PCI driver in the Linux kernel contained a flaw where the error handling path used an incorrect goto label, causing cleanup functions to be skipped. As a result, resources such as rfkill devices, hardware registrations, and debug entries were not freed when a probe failed, leading to memory leaks that could accumulate and potentially destabilize or crash the kernel. The weakness is improper cleanup during driver initialization, mapped to CWE-401.

Affected Systems

All Linux kernel implementations that include the rtlwifi driver prior to the fix are potentially affected. This encompasses kernel packages used by open‑source distributions and vendors that ship kernels with the buggy rtlwifi module. Any kernel lacking the patch commit remains vulnerable, regardless of distribution or version number, due to the lack of explicit version restrictions.

Risk and Exploitability

The CVSS base score of 7.0 rates this as medium severity, while the EPSS score of less than 1% indicates a low likelihood of exploitation. The vulnerability is not listed in CISA KEV. Exploitation would generally require local or privileged access to trigger a probe failure or to influence module loading, making remote exploitation unlikely. The practical risk remains moderate and is contingent on an attacker’s ability to load or manipulate the vulnerable driver.

Generated by OpenCVE AI on September 19, 2026 at 23:27 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Linux kernel to a version that includes the rtlwifi PCI probe error‑handling patch
  • If immediate upgrade is unavailable, blacklist the rtlwifi module to prevent it from loading (e.g., via modprobe.d or blacklist.conf)
  • Monitor system logs for probe‑failure messages or abnormal memory usage related to the rtlwifi driver and apply corrective measures if issues recur

Generated by OpenCVE AI on September 19, 2026 at 23:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sat, 19 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-401

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: wifi: rtlwifi: pci: fix error path in rtl_pci_probe() In the last error path in rtl_pci_probe(), the cleanup functions are skipped due to a wrong goto label. Moreover, the successful call to rtl_init_rfkill(), ieee80211_register_hw(), rtl_debug_add_one() have to be reverted. Fix this issue by updating the labels and adding the relevant cleanup functions to the last error path.
Title wifi: rtlwifi: pci: fix error path in rtl_pci_probe()
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-18T17:55:10.835Z

Reserved: 2026-09-11T19:38:34.811Z

Link: CVE-2026-90403

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:40.100

Modified: 2026-09-18T18:17:57.630

Link: CVE-2026-90403

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T23:30:13Z

Weaknesses
  • CWE-401

    Missing Release of Memory after Effective Lifetime