Executive brief
A vulnerability was identified in the Linux kernel's Realtek Wi-Fi driver (rtw89) that could allow a local user with administrative privileges to cause system instability or potentially access restricted memory. The issue occurs when processing specific configuration commands through the debug interface, which could lead to an out-of-bounds memory access. Because the exploit requires root-level access to the debug file system, the practical risk to most standard operations is considered low.
Technical details
A shift wrapping vulnerability exists in the rtw89_core_mlsr_switch() function within the Realtek rtw89 Wi-Fi driver (drivers/net/wireless/realtek/rtw89/core.c). The 'link_id' parameter, provided by a user via debugfs, was not properly validated against the maximum number of supported links. If a value larger than BITS_PER_LONG is provided, it results in shift wrapping, potentially leading to an out-of-bounds read or write. Exploitation requires local access with root privileges to write to debugfs. The issue has been resolved by enforcing a limit of IEEE80211_MLD_MAX_NUM_LINKS (15) on the link_id.
Affected products
- Linux Linux Kernel 6.16, 6.16.1
Timeline
- 2025-08-22: advisory: NVD publication date
- 2025-05-28: patched: Fix authored by Dan Carpenter