cbcvebase.
CVE-2026-43113
published 2026-05-06

CVE-2026-43113: In the Linux kernel, the following vulnerability has been resolved: wifi: wl1251: validate packet IDs before indexing tx_frames wl1251_tx_packet_cb() uses the…

PriorityP345high8.8CVSS 3.1
AVAACLPRNUINSUCHIHAH
EPSS
0.25%
16.0th percentile
In the Linux kernel, the following vulnerability has been resolved: wifi: wl1251: validate packet IDs before indexing tx_frames wl1251_tx_packet_cb() uses the firmware completion ID directly to index the fixed 16-entry wl->tx_frames[] array. The ID is a raw u8 from the completion block, and the callback does not currently verify that it fits the array before dereferencing it. Reject completion IDs that fall outside wl->tx_frames[] and keep the existing NULL check in the same guard. This keeps the fix local to the trust boundary and avoids touching the rest of the completion flow.

Affected

15 ranges
VendorProductVersion rangeFixed in
linuxlinux
linuxlinux>= 2f01a1f58889fbfeb68b1bc1b52e4197f3333490 < 6509dbece7339dbc8980c706b9d623119a6de1056509dbece7339dbc8980c706b9d623119a6de105
linuxlinux>= 2f01a1f58889fbfeb68b1bc1b52e4197f3333490 < a8a11a876f0a97061ee5d9e61d0f5a0df7e241c7a8a11a876f0a97061ee5d9e61d0f5a0df7e241c7
linuxlinux>= 2f01a1f58889fbfeb68b1bc1b52e4197f3333490 < e0dc1ad870d6788b049bfe1511ac75b2333a7550e0dc1ad870d6788b049bfe1511ac75b2333a7550
linuxlinux>= 2f01a1f58889fbfeb68b1bc1b52e4197f3333490 < b6ba1eacf276063ebeefbbae8056043c24f2efafb6ba1eacf276063ebeefbbae8056043c24f2efaf
linuxlinux>= 2f01a1f58889fbfeb68b1bc1b52e4197f3333490 < df15adc692a802636dd3f258fc7cca8bf7a0ed9adf15adc692a802636dd3f258fc7cca8bf7a0ed9a
linuxlinux>= 2f01a1f58889fbfeb68b1bc1b52e4197f3333490 < 8d7465be5163a923ee5d7459719ef5a021c1584a8d7465be5163a923ee5d7459719ef5a021c1584a
linuxlinux>= 2f01a1f58889fbfeb68b1bc1b52e4197f3333490 < 26ee518695c484f75e3606d631278e84bd24ae0226ee518695c484f75e3606d631278e84bd24ae02
linuxlinux>= 2f01a1f58889fbfeb68b1bc1b52e4197f3333490 < 0fd56fad9c56356e7fa7a7c52e7ecbf807a44eb00fd56fad9c56356e7fa7a7c52e7ecbf807a44eb0
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 2.6.31 < 6.6.1366.6.136
linuxlinux_kernel>= 6.13 < 6.18.246.18.24
linuxlinux_kernel>= 6.19 < 6.19.146.19.14
linuxlinux_kernel>= 6.7 < 6.12.836.12.83

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vendor_oracle9.8CRITICAL
vendor_redhat7.0MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.