wifi: rtw89: fix wrong pci_get_drvdata type in AER handlers
Summary
| CVE | CVE-2026-74413 |
| State | PUBLISHED |
| Assigner | Linux |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-08-15 06:22:43 UTC |
| Updated | 2026-08-15 06:22:43 UTC |
| Description | In the Linux kernel, the following vulnerability has been resolved:
wifi: rtw89: fix wrong pci_get_drvdata type in AER handlers
rtw89 stores an ieee80211_hw pointer via pci_set_drvdata() at probe
time, but io_error_detected() and io_resume() retrieve it as a
net_device pointer. This causes netif_device_detach/attach to
operate on an ieee80211_hw struct, reading and writing at wrong
offsets. The adjacent io_slot_reset() already does it correctly.
Use ieee80211_stop_queues/wake_queues instead, consistent with
every other queue stop/start path in the driver.
Tested on RTL8852CE by calling the handlers from a test module
before and after the fix. |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|
| CNA |
Linux |
Linux |
affected 16e3d93c6183649a3b210f82b83c1cb12aa5e8a3 aefc30e4a829c1683f6ae999df7f9310c27eae6c git |
Not specified |
| CNA |
Linux |
Linux |
affected 16e3d93c6183649a3b210f82b83c1cb12aa5e8a3 c1907b9a4fa9cb33d11a9af138374dd2e93f7a93 git |
Not specified |
| CNA |
Linux |
Linux |
affected 16e3d93c6183649a3b210f82b83c1cb12aa5e8a3 7068c379cf9aa8afe4dce4d9d82390187aa9c4d0 git |
Not specified |
| CNA |
Linux |
Linux |
affected 6.17 |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.17 semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.18.40 6.18.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 7.1.5 7.1.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 7.2-rc1 * original_commit_for_fix |
Not specified |
References
| Reference | Source | Link | Tags |
|---|
| git.kernel.org/stable/c/7068c379cf9aa8afe4dce4d9d82390187aa9c4d0 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/c1907b9a4fa9cb33d11a9af138374dd2e93f7a93 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/aefc30e4a829c1683f6ae999df7f9310c27eae6c |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.