Executive brief
The Linux kernel's RTL8192DU wireless driver contains an array bounds-checking error in packet transmission handling. When processing Wi-Fi Quality of Service (QoS) frames, the driver fails to validate that a QoS Traffic Identifier (TID) value falls within the expected range before using it to access an internal data structure. This can lead to memory corruption or denial of service on systems using this wireless chipset.
Technical details
This is an array-index-out-of-bounds vulnerability in the rtl8192du driver's rtl92du_tx_fill_desc() function. The function retrieves a QoS TID value (range 0–15) from 802.11 frame headers via ieee80211_get_tid() and uses it directly as an array index into sta_entry->tids[], which is allocated with only MAX_TID_COUNT (9) entries. TID values 9–15 cause out-of-bounds access. The vulnerability is triggered via malformed or crafted Wi-Fi frames received on the network interface, requiring no authentication or local access. An attacker can cause kernel memory corruption, information disclosure, or denial of service. A patch was implemented adding a bounds check before array access, matching the fix in the rtl92cu driver.
Affected products
- Linux Linux kernel 5.0 through 6.x (RTL8192DU driver)
Timeline
- 2026-09-11: disclosed: Published on NVD
- 2026-09-07: patched: Fix committed to stable kernel tree by Greg Kroah-Hartman