Bug 2507182 (CVE-2026-64506)

Summary: CVE-2026-64506 kernel: wifi: rtw89: correct drop logic for malformed AMPDU frames
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security DevOps Team <prodsec-dev>
Status: NEW --- QA Contact:
Severity: unspecified Docs Contact:
Priority: unspecified    
Version: unspecifiedCC: rhel-process-autobot, watson-tool-maintainers
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A flaw was found in the Realtek 802.11ac wireless driver (rtw89) within the Linux kernel. A remote attacker, within adjacent network range, could send specially crafted malformed Aggregated MAC Protocol Data Unit (AMPDU) frames. This incorrect handling of frames, particularly during rekey processes, leads to unexpected packet drops. The consequence is a denial of service (DoS), causing affected clients to disconnect from the wireless access point.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description OSIDB Bzimport 2026-07-25 10:09:20 UTC
In the Linux kernel, the following vulnerability has been resolved:

wifi: rtw89: correct drop logic for malformed AMPDU frames

The previous commit aims to fix issue caused by malformed AMPDU frames.
But the drop logic fails to deal with the first AMPDU packet paired with
certain range of sequence number, and leads to unexpected packet drop.
It is more likely to encounter this failure when there are busy traffic
during rekey process and could lead to disconnection from the AP.
Fix this by adding a initial state judgement and only reset status
during pairwise rekey.