GHSA-cq4j-9r28-wxqgHighCVSS 8.8

In the Linux kernel, the following vulnerability has been resolved: wifi: rtw89: fix wrong...

Published
August 15, 2026
Last Modified
August 17, 2026

🔗 CVE IDs covered (1)

📋 Description

In the Linux kernel, the following vulnerability has been resolved:

wifi: rtw89: fix wrong pci_get_drvdata type in AER handlers

rtw89 stores an ieee80211_hw pointer via pci_set_drvdata() at probe time, but io_error_detected() and io_resume() retrieve it as a net_device pointer. This causes netif_device_detach/attach to operate on an ieee80211_hw struct, reading and writing at wrong offsets. The adjacent io_slot_reset() already does it correctly.

Use ieee80211_stop_queues/wake_queues instead, consistent with every other queue stop/start path in the driver.

Tested on RTL8852CE by calling the handlers from a test module before and after the fix.

🔗 References (5)