{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-90403","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-11T19:38:34.811Z","datePublished":"2026-09-17T16:09:32.824Z","dateUpdated":"2026-09-18T17:55:10.835Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-18T17:55:10.835Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: rtlwifi: pci: fix error path in rtl_pci_probe()\n\nIn the last error path in rtl_pci_probe(), the cleanup functions are\nskipped due to a wrong goto label. Moreover, the successful call to\nrtl_init_rfkill(), ieee80211_register_hw(), rtl_debug_add_one() have to\nbe reverted. Fix this issue by updating the labels and adding the\nrelevant cleanup functions to the last error path."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - The UAF is only on rtl_pci_probe()'s last error path, when rtl_pci_intr_mode_decide() fails and the old code jumped to fail3. That path is reached from local_pci_probe() as the .probe of rtl8192ce/rtl8188ee/rtl8192ee/rtl8723be and related pci_driver tables (e.g. Realtek 0x8191/0x8178). 802.11 frames never enter rtl_pci_probe.\nAC:H - The only trigger is pci_enable_msi() or request_irq(pdev->irq, _rtl_pci_interrupt, IRQF_SHARED) failing after ieee80211_register_hw() has already succeeded. pdev->irq is assigned by the host PCI/ACPI code, and the subsequent irqaction kzalloc is tiny compared with earlier ring and wiphy allocations, so an attacker cannot reliably force that failure.\nPR:L - Once fail3 has run ieee80211_free_hw() on the still-registered hw, the leftover default wlan vif from ieee80211_if_add(), cfg80211 wiphy, inetaddr notifiers, and rfkill poll are reachable via nl80211 or any netns address change without init-namespace root or PCI sysfs bind.\nUI:N - No victim must mount media or associate to a network; after the failed probe unwind, the attacker’s own nl80211 use of the leftover wlan vif, an inetaddr change, or cfg80211_rfkill_poll touches the still-registered ieee80211_local.\nS:U - ieee80211_free_hw() frees the still-registered ieee80211_local/wiphy while mac80211 still holds it; impact is host-kernel heap corruption, not a VM, IOMMU, or sandbox escape.\nC:H - fail3 calls ieee80211_free_hw() without ieee80211_unregister_hw(), so cfg80211_rfkill_poll → ieee80211_rfkill_poll and nl80211 still dereference the kfree'd ieee80211_local, wiphy bands, and default STA vif, a UAF read primitive.\nI:H - The leftover objects are written by ieee80211_ifa_changed (inetaddr notifier), mac80211 workqueues never torn down by ieee80211_unregister_hw(), and rtl_op_rfkill_poll via wiphy_rfkill_start_polling, enabling UAF writes and control-flow hijack.\nA:H - ieee80211_free_hw() without ieee80211_unregister_hw() leaves mac80211 workqueues, inetaddr notifiers, the default wlan vif, and rfkill polling running against freed ieee80211_local, which oopses or panics on the next access."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/net/wireless/realtek/rtlwifi/pci.c"],"versions":[{"version":"0c8173385e549f95cd80c3fff5aab87b4f881d8d","lessThan":"2634998247d24be34ba16a7666f31815ef1da00b","status":"affected","versionType":"git"},{"version":"0c8173385e549f95cd80c3fff5aab87b4f881d8d","lessThan":"cfd6824dd1d151ab3abc00117b3774c8056006e0","status":"affected","versionType":"git"},{"version":"0c8173385e549f95cd80c3fff5aab87b4f881d8d","lessThan":"86e6187f8525c8f8219eb49e022eba854cc6ab86","status":"affected","versionType":"git"},{"version":"0c8173385e549f95cd80c3fff5aab87b4f881d8d","lessThan":"aef178ffae5420afdbf46f7133ed28bd4248e15c","status":"affected","versionType":"git"},{"version":"0c8173385e549f95cd80c3fff5aab87b4f881d8d","lessThan":"b42fcfb097da46f0e86564736ced939e83cb8442","status":"affected","versionType":"git"},{"version":"0c8173385e549f95cd80c3fff5aab87b4f881d8d","lessThan":"a89818977338ba71194b1ab1d071f0c0848b1e13","status":"affected","versionType":"git"},{"version":"0c8173385e549f95cd80c3fff5aab87b4f881d8d","lessThan":"1b68b6e529ce75112fab98e89583a76370ca394b","status":"affected","versionType":"git"},{"version":"0c8173385e549f95cd80c3fff5aab87b4f881d8d","lessThan":"3c2999d13eeb222ae56631aeb7ca248090f2b210","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/net/wireless/realtek/rtlwifi/pci.c"],"versions":[{"version":"2.6.38","status":"affected"},{"version":"0","lessThan":"2.6.38","status":"unaffected","versionType":"semver"},{"version":"5.10.270","lessThanOrEqual":"5.10.*","status":"unaffected","versionType":"semver"},{"version":"5.15.221","lessThanOrEqual":"5.15.*","status":"unaffected","versionType":"semver"},{"version":"6.1.188","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.157","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.110","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.52","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2.6","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.38","versionEndExcluding":"5.10.270"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.38","versionEndExcluding":"5.15.221"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.38","versionEndExcluding":"6.1.188"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.38","versionEndExcluding":"6.6.157"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.38","versionEndExcluding":"6.12.110"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.38","versionEndExcluding":"6.18.52"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.38","versionEndExcluding":"7.2.6"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.38","versionEndExcluding":"7.3-rc1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/2634998247d24be34ba16a7666f31815ef1da00b"},{"url":"https://git.kernel.org/stable/c/cfd6824dd1d151ab3abc00117b3774c8056006e0"},{"url":"https://git.kernel.org/stable/c/86e6187f8525c8f8219eb49e022eba854cc6ab86"},{"url":"https://git.kernel.org/stable/c/aef178ffae5420afdbf46f7133ed28bd4248e15c"},{"url":"https://git.kernel.org/stable/c/b42fcfb097da46f0e86564736ced939e83cb8442"},{"url":"https://git.kernel.org/stable/c/a89818977338ba71194b1ab1d071f0c0848b1e13"},{"url":"https://git.kernel.org/stable/c/1b68b6e529ce75112fab98e89583a76370ca394b"},{"url":"https://git.kernel.org/stable/c/3c2999d13eeb222ae56631aeb7ca248090f2b210"}],"title":"wifi: rtlwifi: pci: fix error path in rtl_pci_probe()","x_generator":{"engine":"bippy-1.2.0"}}}}