Description
In the Linux kernel, the following vulnerability has been resolved:

wifi: rtw89: debug: fix off by on in rtw89_ppdu_str()

This > comparison should be >= to avoid an out of bounds access.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Out-of-bounds memory access
Action: Assess
AI Analysis

Impact

This vulnerability stems from an off‑by‑one error in the Linux wireless driver rtw89, where a comparison should use >= instead of >, allowing a buffer index to exceed the bounds of an array during debug string generation. The faulty logic can lead to a memory read or write outside the intended bounds, potentially corrupting data, leaking information, or causing a crash. The impact is limited to memory corruption rather than escalation of privileges, but could still disrupt device stability or expose sensitive data within the kernel context.

Affected Systems

All Linux installations that include the rtw89 wireless driver may be affected, regardless of specific version, unless the patch has already been incorporated into the kernel. Specific affected releases are not enumerated in the available data.

Risk and Exploitability

The vulnerability is listed with an EPSS score of less than 1%, indicating a very low likelihood of exploitation, and it is not cataloged in CISA KEV. Because the flaw exists in a debug routine, an attacker would likely require local access or elevated privileges to exercise the vulnerable code path, reducing practical risk. Nonetheless, the out-of-bounds access could lead to kernel crashes or data leakage if triggered, so assessment of whether the driver is active or debug logging is enabled is prudent.

Generated by OpenCVE AI on September 19, 2026 at 07:36 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Linux kernel to a version that includes the patch fixing the rtw89_ppdu_str() comparison error
  • Reboot the system to boot into the updated kernel and verify the driver is now using the corrected logic
  • If the updated kernel is unavailable, consider disabling rtw89 debug logging or removing the driver until a suitable kernel update can be applied

Generated by OpenCVE AI on September 19, 2026 at 07:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 08:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-787

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: wifi: rtw89: debug: fix off by on in rtw89_ppdu_str() This > comparison should be >= to avoid an out of bounds access.
Title wifi: rtw89: debug: fix off by on in rtw89_ppdu_str()
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:11:58.577Z

Reserved: 2026-09-17T16:02:15.090Z

Link: CVE-2026-93166

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:18:12.143

Modified: 2026-09-17T17:18:12.143

Link: CVE-2026-93166

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T21:30:16Z

Weaknesses