CVE Database
/

CVE-2026-43172

Back to search

CVE-2026-43172

Published: May 6, 2026

Modified: May 11, 2026

PUBLISHED

CVSS v3.1

8.8

HIGH

Description

In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: fix 22000 series SMEM parsing If the firmware were to report three LMACs (which doesn't exist in hardware) then using "fwrt->smem_cfg.lmac[2]" is an overrun of the array. Reject such and use IWL_FW_CHECK instead of WARN_ON in this function.

VendorProductVersions

Linux

Linux

affected
ebfa7f8ae155c9a0bb2e4038d6b5d8b14881c424 - < 1d49a42717bdc8de77eabeb5b7d3e88d141ffea9
affected
ebfa7f8ae155c9a0bb2e4038d6b5d8b14881c424 - < 2b4b1510aaaf5b9fb57327ecffc20c055f61f205
affected
ebfa7f8ae155c9a0bb2e4038d6b5d8b14881c424 - < 58192b9ce09b0f0f86e2036683bd542130b91a98

Linux

Linux

affected
5.8
unaffected
0 - < 5.8
unaffected
6.18.16 - <= 6.18.*
unaffected
6.19.6 - <= 6.19.*
unaffected
7.0 - <= *

CVSS v3.1 Details

CVSS v3.1 Vector

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Attack Vector

Adjacent

Attack Complexity

Low

Privileges Required

None

User Interaction

None

Scope

Unchanged

Confidentiality

High

Integrity

High

Availability

High

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now