wifi: rtw88: fix OOB read from firmware RX descriptor exceeding DMA buffer

Summary

CVECVE-2026-74410
StatePUBLISHED
AssignerLinux
Source PriorityCVE Program / NVD first with legacy fallback
Published2026-08-15 06:22:43 UTC
Updated2026-08-15 06:22:43 UTC
DescriptionIn the Linux kernel, the following vulnerability has been resolved: wifi: rtw88: fix OOB read from firmware RX descriptor exceeding DMA buffer In rtw_pci_rx_napi(), new_len is computed as the sum of pkt_len (14-bit descriptor field, max 16383) and pkt_offset (drv_info_sz + shift, both firmware-controlled). The result can exceed RTK_PCI_RX_BUF_SIZE (11478), causing an out-of-bounds read from the pre-allocated DMA buffer when skb_put_data copies new_len bytes. The USB transport already validates this (rtw_usb_rx_data_put checks against RTW_USB_MAX_RECVBUF_SZ); the PCIe path does not. Add a check that new_len does not exceed the DMA buffer size.

Vendor Declared Affected Products

SourceVendorProductVersionPlatforms
CNA Linux Linux affected e3037485c68ec1a299ff41160d8fedbd4abc29b9 913bd7d3d3d842b5c1d2b908a0201efa8fc79793 git Not specified
CNA Linux Linux affected e3037485c68ec1a299ff41160d8fedbd4abc29b9 45abc14ab3f15da7d689f1a8809c1a01240a94d9 git Not specified
CNA Linux Linux affected e3037485c68ec1a299ff41160d8fedbd4abc29b9 08193e733e5d4790e6c937af86d78793b02709be git Not specified
CNA Linux Linux affected e3037485c68ec1a299ff41160d8fedbd4abc29b9 6a3c384393d3f0b41669ed5a2e88744aad9d87c8 git Not specified
CNA Linux Linux affected e3037485c68ec1a299ff41160d8fedbd4abc29b9 26c183a86ea4dd1f2ff90c6f783649e7f5722a10 git Not specified
CNA Linux Linux affected e3037485c68ec1a299ff41160d8fedbd4abc29b9 01155ded5d4dad61840a9a3c33ab56778ef1f100 git Not specified
CNA Linux Linux affected e3037485c68ec1a299ff41160d8fedbd4abc29b9 1554fa522f16ec7c5c342ad33fe734eeb6eb2452 git Not specified
CNA Linux Linux affected e3037485c68ec1a299ff41160d8fedbd4abc29b9 6e76e9ed273dfb4b3333a5ebbb94958cc5752ab6 git Not specified
CNA Linux Linux affected 5.2 Not specified
CNA Linux Linux unaffected 5.2 semver Not specified
CNA Linux Linux unaffected 5.10.261 5.10.* semver Not specified
CNA Linux Linux unaffected 5.15.212 5.15.* semver Not specified
CNA Linux Linux unaffected 6.1.178 6.1.* semver Not specified
CNA Linux Linux unaffected 6.6.145 6.6.* semver Not specified
CNA Linux Linux unaffected 6.12.97 6.12.* semver Not specified
CNA Linux Linux unaffected 6.18.40 6.18.* semver Not specified
CNA Linux Linux unaffected 7.1.5 7.1.* semver Not specified
CNA Linux Linux unaffected 7.2-rc1 * original_commit_for_fix Not specified

References

ReferenceSourceLinkTags
git.kernel.org/stable/c/913bd7d3d3d842b5c1d2b908a0201efa8fc79793 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/01155ded5d4dad61840a9a3c33ab56778ef1f100 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/6e76e9ed273dfb4b3333a5ebbb94958cc5752ab6 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/26c183a86ea4dd1f2ff90c6f783649e7f5722a10 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/45abc14ab3f15da7d689f1a8809c1a01240a94d9 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/6a3c384393d3f0b41669ed5a2e88744aad9d87c8 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/08193e733e5d4790e6c937af86d78793b02709be 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/1554fa522f16ec7c5c342ad33fe734eeb6eb2452 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
CVE Program record CVE.ORG www.cve.org canonical
NVD vulnerability detail NVD nvd.nist.gov canonical, analysis

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report