PatchSiren cyber security CVE debrief
CVE-2026-72005 Linux CVE debrief
The Linux kernel's rt2x00 wifi driver has a vulnerability (CVE-2026-72005) that can cause a denial of service or potentially allow a local attacker to execute arbitrary code. The vulnerability occurs when the rt2x00lib_probe_dev() function uses the full rt2x00lib_remove_dev() teardown for all probe failures. However, drv_data allocation and workqueue allocation can fail before intf_work, autowakeup_work, and sleep_work have been initialized. This issue was found by a static analysis tool and confirmed by manual review. A QEMU PoC was used to force alloc_ordered_workqueue() to fail before the work initializers are reached.
- Vendor
- Linux
- Product
- Unknown
- CVSS
- Unknown
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-15
- Original CVE updated
- 2026-08-15
- Advisory published
- 2026-08-15
- Advisory updated
- 2026-08-15
Who should care
Linux kernel developers, Linux distribution maintainers, and users of Linux-based systems that utilize the rt2x00 wifi driver should be aware of this vulnerability and take necessary actions to secure their systems. The vulnerability affects the Linux kernel, specifically the rt2x00 wifi driver, and a local attacker could exploit this vulnerability to cause a denial of service or potentially execute arbitrary code. Linux kernel developers should review and update Linux kernel configurations to ensure rt2x00 wifi driver is properly secured. Linux distribution maintainers should apply the official patch or update to a fixed version of the Linux kernel. Users of Linux-based systems should monitor Linux kernel logs for suspicious activity related to rt2x00 wifi driver. Security teams should review compensating controls for exposed systems while remediation is scheduled and verified. Vulnerability management teams should track exceptions, retest remediated assets, and close the item only after evidence is documented. Asset inventory teams should confirm whether affected product deployments exist in managed environments and assign an owner for follow-up. Monitoring and detection teams should check relevant monitoring, detection, and logs for exposed assets that need extra review. IT teams should plan vendor-supported updates or mitigations through normal change control where exposure is confirmed. Penetration testing teams should review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance. Compliance teams should ensure that the necessary steps are taken to comply with regulatory requirements. Incident response teams should be prepared to respond to potential exploits of this vulnerability. Security awareness teams should educate users about the risks associated with this vulnerability and the importance of applying patches or updates. Business continuity teams should ensure that business continuity plans are in place in case of an exploit. Risk management teams should assess the risk associated with this vulnerability and prioritize remediation efforts accordingly. Compliance and audit teams should ensure that the rem
Technical summary
The rt2x00lib_probe_dev() function in the Linux kernel's rt2x00 wifi driver has a vulnerability. When probe failures occur, the function uses the full rt2x00lib_remove_dev() teardown. However, drv_data allocation and workqueue allocation can fail before intf_work, autowakeup_work, and sleep_work have been initialized. This can cause a denial of service or potentially allow a local attacker to execute arbitrary code.
Defensive priority
This vulnerability affects the Linux kernel, specifically the rt2x00 wifi driver. A local attacker could exploit this vulnerability to cause a denial of service or potentially execute arbitrary code.
Recommended defensive actions
- Apply the official patch or update to a fixed version of the Linux kernel
- Review and update Linux kernel configurations to ensure rt2x00 wifi driver is properly secured
- Monitor Linux kernel logs for suspicious activity related to rt2x00 wifi driver
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
- Review compensating controls for exposed systems while remediation is scheduled and verified.
Evidence notes
The CVE-2026-72005 vulnerability was found in the Linux kernel's rt2x00 wifi driver. The vulnerability occurs when the rt2x00lib_probe_dev() function uses the full rt2x00lib_remove_dev() teardown for all probe failures. However, drv_data allocation and workqueue allocation can fail before intf_work, autowakeup_work, and sleep_work have been initialized. A QEMU PoC was used to force alloc_ordered_workqueue() to fail before the work initializers are reached.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-72005 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-72005
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-72005 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-72005
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/3c0427d719bddb33caf18ff4ffb77cb47de7eb00
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/536fb3d739d75a03cb318c0c6fe799425cfea501
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/56994852d704535ea354a4627ca667b1b4fa0deb
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/59afe6148927395cf86f9429900e029a48b1d42b
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/66bd9b1a72de7c2f5141b02d796048aafaed8a49
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/816559409e340acaa5c9d868291dab30d8c80263
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/8b58d1f1356df6a7d2de3f55bb665b18b04ffda0
416baaa9-dc9f-4396-8d5f-8c081fb06d67
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.