CVE-2026-43213Disclosure(linux / linux_kernel)

LOWCVSS 7.5 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch linux linux_kernel systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

In the Linux kernel, the following vulnerability has been resolved: wifi: rtw89: pci: validate sequence number of TX release report Hardware rarely reports abnormal sequence number in TX release report, which will access out-of-bounds of wd_ring->pages array, causing NULL pointer dereference. BUG: kernel NULL pointer dereference, address: 0000000000000000 #PF: supervisor read access in kernel mode #PF: error_code(0x0000) - not-present page PGD 0 P4D 0 Oops: 0000 [#1] PREEMPT SMP NOPTI CPU: 1 PID: 1085 Comm: irq/129-rtw89_p Tainted: G S U 6.1.145-17510-g2f3369c91536 #1 (HASH:69e8 1) Call Trace: <IRQ> rtw89_pci_release_tx+0x18f/0x300 [rtw89_pci (HASH:4c83 2)] rtw89_pci_napi_poll+0xc2/0x190 [rtw89_pci (HASH:4c83 2)] net_rx_action+0xfc/0x460 net/core/dev.c:6578 net/core/dev.c:6645 net/core/dev.c:6759 handle_softirqs+0xbe/0x290 kernel/softirq.c:601 ? rtw89_pci_interrupt_threadfn+0xc5/0x350 [rtw89_pci (HASH:4c83 2)] __local_bh_enable_ip+0xeb/0x120 kernel/softirq.c:499 kernel/softirq.c:423 </IRQ> <TASK> rtw89_pci_interrupt_threadfn+0xf8/0x350 [rtw89_pci (HASH:4c83 2)] ? irq_thread+0xa7/0x340 kernel/irq/manage.c:0 irq_thread+0x177/0x340 kernel/irq/manage.c:1205 kernel/irq/manage.c:1314 ? thaw_kernel_threads+0xb0/0xb0 kernel/irq/manage.c:1202 ? irq_forced_thread_fn+0x80/0x80 kernel/irq/manage.c:1220 kthread+0xea/0x110 kernel/kthread.c:376 ? synchronize_irq+0x1a0/0x1a0 kernel/irq/manage.c:1287 ? kthread_associate_blkcg+0x80/0x80 kernel/kthread.c:331 ret_from_fork+0x1f/0x30 arch/x86/entry/entry_64.S:295 </TASK> To prevent crash, validate rpp_info.seq before using.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-476

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • linux_kernel

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • 2 total mentions across 1 day

Affected systems

Vendors
Products
linux_kernel

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-05-07: 2Patch / Workaround · 2026-05-07: 1Technical Details · 2026-05-07: 205-07
Signal classification2 categories
Disclosure
150.0%
Patch
150.0%
Referenced assets2 URLs
Full discourse2 posts
  • WindowsForum@windowsforum
    Patch

    🚨 CVE-2026-43213 fixes rtw89 Wi‑Fi crashes via “sequence validation”… aka Windows taught Linux that “trust packets” is a bad life choice. Crashes still matter: uptime is security. #Windows #Linux #Security https://windowsforum.com/threads/cve-2026-43213-linux-rtw89-wi-fi-kernel-crash-fixed-by-sequence-validation.416771/?utm_source=x&utm_medium=social&utm_campaign=news_node84 #LinuxKernel #DriverSecurity #CveVulnerability https://t.co/RORhbZxRu4

    Post summary

    The community post announces that CVE‑2026‑43213, a crash vulnerability in the rtw89 Wi‑Fi driver, has been addressed using sequence validation. No proof‑of‑concept, exploit code, or evidence of active exploitation is provided.

    0000045
    1.1K followersView on X
  • WindowsForum@windowsforum
    Disclosure

    🪟 CVE-2026-43213 in Realtek rtw89: not RCE, just a malformed TX seq number that faceplants the kernel. “Small driver assumption” = classic Wi‑Fi rage, especially on fleets. #Windows #Security #Linux https://windowsforum.com/threads/cve-2026-43213-realtek-rtw89-kernel-crash-seq-number-validation-fix.416774/?utm_source=x&utm_medium=social&utm_campaign=news_node84 #LinuxKernel #CveSecurity #WiFiDriver #RealtekRtw89 https://t.co/sxSZMrK7Du

    Post summary

    The tweet announces CVE‑2026‑43213, a kernel crash in Realtek rtw89 due to a malformed TX sequence number, providing basic technical details but no PoC, exploit, or patch information.

    0000049
    1.1K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
OSlinuxlinux_kernel---

Explore more