PatchSiren cyber security CVE debrief
CVE-2026-74410 Linux CVE debrief
The Linux kernel has a vulnerability in the rtw88 wifi driver that allows for an out-of-bounds read from a firmware RX descriptor exceeding the DMA buffer. This occurs when the new_len value computed from pkt_len and pkt_offset exceeds the RTK_PCI_RX_BUF_SIZE, causing an out-of-bounds read when skb_put_data copies new_len bytes. The vulnerability can lead to potential data exposure or system instability. Defenders should assess exposure and prioritize patching vulnerable systems, particularly those with exposed wifi interfaces.
- Vendor
- Linux
- Product
- Unknown
- CVSS
- HIGH 8.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-15
- Original CVE updated
- 2026-08-15
- Advisory published
- 2026-08-15
- Advisory updated
- 2026-08-15
Who should care
Defenders responsible for Linux kernel systems with exposed wifi interfaces should assess exposure and prioritize patching vulnerable systems. They should also verify DMA buffer sizes and firmware RX descriptor validation, and monitor for potential unusual activity on wifi interfaces. Additionally, defenders should review compensating controls for exposed systems while remediation is scheduled and verified.
Why it matters
The Linux kernel vulnerability in the rtw88 wifi driver allows for an out-of-bounds read, potentially leading to data exposure or system instability. Defenders should prioritize patching vulnerable systems, particularly those with exposed wifi interfaces, and monitor for potential unusual activity.
- Potential data exposure or corruption due to out-of-bounds read
- Possible system crashes or instability due to invalid data processing
- Need for verification of DMA buffer sizes and firmware RX descriptor validation
- Priority for patching vulnerable systems, especially those with exposed wifi interfaces
Technical summary
The rtw_pci_rx_napi() function in the Linux kernel's rtw88 wifi driver does not validate the new_len value computed from pkt_len and pkt_offset, leading to an out-of-bounds read from the pre-allocated DMA buffer when skb_put_data copies new_len bytes. The vulnerability can cause potential data exposure or system instability. The issue arises from the lack of validation of the new_len value, which can exceed the RTK_PCI_RX_BUF_SIZE, causing an out-of-bounds read. Defenders should prioritize patching vulnerable systems, particularly those with exposed wifi interfaces.
Defensive priority
Defenders should prioritize patching vulnerable systems, particularly those with exposed wifi interfaces, and monitor for potential unusual activity.
Recommended defensive actions
- Patch vulnerable Linux kernel systems, especially those with exposed wifi interfaces
- Monitor for unusual activity on wifi interfaces
- Verify DMA buffer sizes and firmware RX descriptor validation
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
The CVE record and NVD entry provide details on the vulnerability, but do not specify which kernel versions are affected or provide additional information on exploitation. The Linux kernel's rtw88 wifi driver does not validate the new_len value computed from pkt_len and pkt_offset, leading to an out-of-bounds read from the pre-allocated DMA buffer when skb_put_data copies new_len bytes. There is no indication of exploitation in the wild, but defenders should verify DMA buffer sizes and firmware RX descriptor validation.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-74410 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-74410
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-74410 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-74410
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/01155ded5d4dad61840a9a3c33ab56778ef1f100
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/08193e733e5d4790e6c937af86d78793b02709be
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/1554fa522f16ec7c5c342ad33fe734eeb6eb2452
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/26c183a86ea4dd1f2ff90c6f783649e7f5722a10
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/45abc14ab3f15da7d689f1a8809c1a01240a94d9
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/6a3c384393d3f0b41669ed5a2e88744aad9d87c8
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/6e76e9ed273dfb4b3333a5ebbb94958cc5752ab6
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/913bd7d3d3d842b5c1d2b908a0201efa8fc79793
416baaa9-dc9f-4396-8d5f-8c081fb06d67
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.