PT-2026-37512 · Linux · Linux Kernel

Published

2026-05-06

·

Updated

2026-05-07

·

CVE-2026-43172

CVSS v3.1

8.8

High

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A flaw exists in the iwlwifi driver regarding the parsing of SMEM (Shared Memory) in the 22000 series. An array overrun occurs when the firmware reports three LMACs (Lower MAC addresses), leading to an out-of-bounds access when referencing fwrt->smem cfg.lmac[2]. This happens because the hardware does not support three LMACs, and the driver fails to properly validate the firmware report.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Related Identifiers

CVE-2026-43172

Affected Products

Linux Kernel