CVE-2026-80943
Received Received - Intake

Buffer Overflow in Linux Kernel RTL8192DU WiFi Driver

Vulnerability report for CVE-2026-80943, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-11

Last updated on: 2026-09-13

Assigner: kernel.org

Description

In the Linux kernel, the following vulnerability has been resolved: wifi: rtlwifi: rtl8192du: check QoS TID before indexing tids rtl92du_tx_fill_desc() uses ieee80211_get_tid() to read the QoS TID from the 802.11 header and then uses it as an index into sta_entry->tids[]. ieee80211_get_tid() returns the low 4-bit QoS TID value, so the result can be in the range 0..15. rtlwifi only allocates MAX_TID_COUNT entries for sta_entry->tids[], and MAX_TID_COUNT is 9. A QoS TID greater than 8 therefore indexes past the aggregation state array. Keep the default RTL_AGG_STOP state for out-of-range TIDs, matching rtl92cu_tx_fill_desc(). This issue was detected by our static analysis tool and confirmed by manual audit. UBSAN validation for the same bug pattern reports an array-index-out-of-bounds access with index 10 for type 'rtl_tid_data [9]'.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-11
Last Modified
2026-09-13
Generated
2026-10-02
AI Q&A
2026-09-12
EPSS Evaluated
2026-10-01
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
linux linux_kernel *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is an array-index-out-of-bounds vulnerability in the Linux kernel's RTL8192DU WiFi driver. The function rtl92du_tx_fill_desc() reads a QoS TID value from an 802.11 header and uses it to index into an array sta_entry->tids[]. The array is only allocated for 9 entries (MAX_TID_COUNT=9), but the TID value can be 0-15. Accessing an index beyond 8 causes an out-of-bounds write.

Detection Guidance

This vulnerability is specific to the Linux kernel's RTL8192DU WiFi driver and involves an array-index-out-of-bounds issue. Detection requires checking if your system uses the affected driver version. Inspect kernel logs for UBSAN warnings about array-index-out-of-bounds in rtl_tid_data. No direct commands are provided, but monitoring kernel logs for related errors may indicate exploitation or presence of the vulnerable code.

Impact Analysis

This flaw could allow an attacker within WiFi range to trigger undefined behavior, potentially causing system crashes, data corruption, or privilege escalation. It may lead to denial-of-service conditions or unauthorized access if exploited.

Compliance Impact

This vulnerability is a low-level kernel memory safety issue in the Linux WiFi driver (rtlwifi) that could lead to out-of-bounds array access. It does not directly relate to data privacy, encryption, or access controls typically addressed by GDPR or HIPAA. Compliance impact would depend on whether this flaw could be exploited to access or manipulate sensitive data, but no evidence suggests such a connection.

Mitigation Strategies

Update your Linux kernel to the latest stable version where this vulnerability is patched. If using a custom or older kernel, apply the patch for the RTL8192DU driver. Disable the affected WiFi driver if not essential. Monitor kernel security advisories for updates related to this CVE.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-80943. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart