CVE-2026-46092 (GCVE-0-2026-46092)
Vulnerability from cvelistv5
Published
2026-05-27 12:58
Modified
2026-07-16 11:13
Severity ?
Summary
In the Linux kernel, the following vulnerability has been resolved: wifi: rtw88: check for PCI upstream bridge existence pci_upstream_bridge() returns NULL if the device is on a root bus. If 8821CE is installed in the system with such a PCI topology, the probing routine will crash. This has probably been unnoticed as 8821CE is mostly supplied in laptops where there is a PCI-to-PCI bridge located upstream from the device. However the card might be installed on a system with different configuration. Check if the bridge does exist for the specific workaround to be applied. Found by Linux Verification Center (linuxtesting.org) with Svace static analysis tool.
Impacted products
Vendor Product Version
Linux Linux Version: 617339466fda09916c4b4151fa5e6a9c1fdae353
Version: 24f5e38a13b5ae2b6105cda8bb47c19108e62a9a
Version: 24f5e38a13b5ae2b6105cda8bb47c19108e62a9a
Version: 24f5e38a13b5ae2b6105cda8bb47c19108e62a9a
Version: 24f5e38a13b5ae2b6105cda8bb47c19108e62a9a
Version: 24f5e38a13b5ae2b6105cda8bb47c19108e62a9a
Version: 24f5e38a13b5ae2b6105cda8bb47c19108e62a9a
Version: f21e8cb927fa9da49490b74ddda3856a828b82d6
Version: 5.15.17   
Version: 5.16.3   
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "Linux",
          "programFiles": [
            "drivers/net/wireless/realtek/rtw88/pci.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "lessThan": "959c13da6c36167ce1016d400a6104d2367f686e",
              "status": "affected",
              "version": "617339466fda09916c4b4151fa5e6a9c1fdae353",
              "versionType": "git"
            },
            {
              "lessThan": "3b89b4c095804c478d50376285e66700cf3c045f",
              "status": "affected",
              "version": "24f5e38a13b5ae2b6105cda8bb47c19108e62a9a",
              "versionType": "git"
            },
            {
              "lessThan": "cc9b6303e7ea91bc360b42c7edc1fe9ceb2f47fe",
              "status": "affected",
              "version": "24f5e38a13b5ae2b6105cda8bb47c19108e62a9a",
              "versionType": "git"
            },
            {
              "lessThan": "6c53d68e3bcfc8faccdd76c3383a9232b05c9ae6",
              "status": "affected",
              "version": "24f5e38a13b5ae2b6105cda8bb47c19108e62a9a",
              "versionType": "git"
            },
            {
              "lessThan": "000134a20bbf89b1152520a2eef71f91fdb83a5b",
              "status": "affected",
              "version": "24f5e38a13b5ae2b6105cda8bb47c19108e62a9a",
              "versionType": "git"
            },
            {
              "lessThan": "3bbbb56204f7359ce2139a9341b43b52a186261c",
              "status": "affected",
              "version": "24f5e38a13b5ae2b6105cda8bb47c19108e62a9a",
              "versionType": "git"
            },
            {
              "lessThan": "eb101d2abdcccb514ca4fccd3b278dd8267374f6",
              "status": "affected",
              "version": "24f5e38a13b5ae2b6105cda8bb47c19108e62a9a",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "f21e8cb927fa9da49490b74ddda3856a828b82d6",
              "versionType": "git"
            },
            {
              "lessThan": "5.15.210",
              "status": "affected",
              "version": "5.15.17",
              "versionType": "semver"
            },
            {
              "lessThan": "5.17",
              "status": "affected",
              "version": "5.16.3",
              "versionType": "semver"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Linux",
          "programFiles": [
            "drivers/net/wireless/realtek/rtw88/pci.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "5.17"
            },
            {
              "lessThan": "5.17",
              "status": "unaffected",
              "version": "0",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "5.15.*",
              "status": "unaffected",
              "version": "5.15.210",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.1.*",
              "status": "unaffected",
              "version": "6.1.175",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.6.*",
              "status": "unaffected",
              "version": "6.6.140",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.12.*",
              "status": "unaffected",
              "version": "6.12.86",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.18.*",
              "status": "unaffected",
              "version": "6.18.27",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "7.0.*",
              "status": "unaffected",
              "version": "7.0.4",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "*",
              "status": "unaffected",
              "version": "7.1",
              "versionType": "original_commit_for_fix"
            }
          ]
        }
      ],
      "cpeApplicability": [
        {
          "nodes": [
            {
              "cpeMatch": [
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "5.15.210",
                  "versionStartIncluding": "5.15.17",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.1.175",
                  "versionStartIncluding": "5.17",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.6.140",
                  "versionStartIncluding": "5.17",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.12.86",
                  "versionStartIncluding": "5.17",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.18.27",
                  "versionStartIncluding": "5.17",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "7.0.4",
                  "versionStartIncluding": "5.17",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "7.1",
                  "versionStartIncluding": "5.17",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionStartIncluding": "5.16.3",
                  "vulnerable": true
                }
              ],
              "negate": false,
              "operator": "OR"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: rtw88: check for PCI upstream bridge existence\n\npci_upstream_bridge() returns NULL if the device is on a root bus.  If\n8821CE is installed in the system with such a PCI topology, the probing\nroutine will crash.  This has probably been unnoticed as 8821CE is mostly\nsupplied in laptops where there is a PCI-to-PCI bridge located upstream\nfrom the device.  However the card might be installed on a system with\ndifferent configuration.\n\nCheck if the bridge does exist for the specific workaround to be applied.\n\nFound by Linux Verification Center (linuxtesting.org) with Svace static\nanalysis tool."
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-07-16T11:13:51.937Z",
        "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "shortName": "Linux"
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/959c13da6c36167ce1016d400a6104d2367f686e"
        },
        {
          "url": "https://git.kernel.org/stable/c/3b89b4c095804c478d50376285e66700cf3c045f"
        },
        {
          "url": "https://git.kernel.org/stable/c/cc9b6303e7ea91bc360b42c7edc1fe9ceb2f47fe"
        },
        {
          "url": "https://git.kernel.org/stable/c/6c53d68e3bcfc8faccdd76c3383a9232b05c9ae6"
        },
        {
          "url": "https://git.kernel.org/stable/c/000134a20bbf89b1152520a2eef71f91fdb83a5b"
        },
        {
          "url": "https://git.kernel.org/stable/c/3bbbb56204f7359ce2139a9341b43b52a186261c"
        },
        {
          "url": "https://git.kernel.org/stable/c/eb101d2abdcccb514ca4fccd3b278dd8267374f6"
        }
      ],
      "title": "wifi: rtw88: check for PCI upstream bridge existence",
      "x_generator": {
        "engine": "bippy-1.2.0"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
    "assignerShortName": "Linux",
    "cveId": "CVE-2026-46092",
    "datePublished": "2026-05-27T12:58:37.088Z",
    "dateReserved": "2026-05-13T15:03:33.097Z",
    "dateUpdated": "2026-07-16T11:13:51.937Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}


Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Sightings

Author Source Type Date

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
  • Confirmed: The vulnerability is confirmed from an analyst perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
  • Patched: This vulnerability was successfully patched by the user reporting the sighting.
  • Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
  • Not confirmed: The user expresses doubt about the veracity of the vulnerability.
  • Not patched: This vulnerability was not successfully patched by the user reporting the sighting.


Loading…

Loading…