Bug 2540546 (CVE-2026-97516) - CVE-2026-97516 kernel: wifi: rtw88: Add NULL check for chip->edcca_th in rtw_fw_adaptivity_result()
Summary: CVE-2026-97516 kernel: wifi: rtw88: Add NULL check for chip->edcca_th in rtw_...
Keywords:
Status: NEW
Alias: CVE-2026-97516
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
low
low
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-09-24 17:11 UTC by OSIDB Bzimport
Modified: 2026-09-28 17:13 UTC (History)
17 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-09-24 17:11:23 UTC
In the Linux kernel, the following vulnerability has been resolved:

wifi: rtw88: Add NULL check for chip->edcca_th in rtw_fw_adaptivity_result()

It was recently reported that rtw_fw_adaptivity_result()
in fw.c dereferences rtwdev->chip->edcca_th without
a NULL check. The issue is that devices with the
8821CE chip don't define edcca_th in their chip
info. As a result, when rtw_fw_adaptivity_result()
tries to dereference it, the kernel triggers an oops.

Add a NULL check for edcca_th before dereferencing
it in rtw_fw_adaptivity_result() in fw.c. Placing
the check at the function entry avoids logging any
garbage values.

This change does not address the root cause for
this behavior, but it prevents the NULL dereference
and the resulting oops while a more permanent solution
is developed.

Tested on a 8822CE chip which defines edcca_th, so
this issue is not present on it, but it still uses
this driver and I can verify there are no regressions.


Note You need to log in before you can comment on or make changes to this bug.