CVE-2026-43172
published 2026-05-06CVE-2026-43172: In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: fix 22000 series SMEM parsing If the firmware were to report three LMACs…
PriorityP344high8.8CVSS 3.1
AVAACLPRNUINSUCHIHAH
EPSS
0.26%
17.3th percentile
In the Linux kernel, the following vulnerability has been resolved:
wifi: iwlwifi: fix 22000 series SMEM parsing
If the firmware were to report three LMACs (which doesn't
exist in hardware) then using "fwrt->smem_cfg.lmac[2]" is
an overrun of the array. Reject such and use IWL_FW_CHECK
instead of WARN_ON in this function.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| linux | linux | — | — |
| linux | linux | >= ebfa7f8ae155c9a0bb2e4038d6b5d8b14881c424 < 1d49a42717bdc8de77eabeb5b7d3e88d141ffea9 | 1d49a42717bdc8de77eabeb5b7d3e88d141ffea9 |
| linux | linux | >= ebfa7f8ae155c9a0bb2e4038d6b5d8b14881c424 < 2b4b1510aaaf5b9fb57327ecffc20c055f61f205 | 2b4b1510aaaf5b9fb57327ecffc20c055f61f205 |
| linux | linux | >= ebfa7f8ae155c9a0bb2e4038d6b5d8b14881c424 < 58192b9ce09b0f0f86e2036683bd542130b91a98 | 58192b9ce09b0f0f86e2036683bd542130b91a98 |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 5.8 < 6.18.16 | 6.18.16 |
| linux | linux_kernel | >= 6.19 < 6.19.6 | 6.19.6 |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vendor_redhat7.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kernel: wifi: iwlwifi: fix 22000 series SMEM parsing
vendor_redhat·2026-05-06·CVSS 7.0
CVE-2026-43172 [MEDIUM] CWE-1285 kernel: wifi: iwlwifi: fix 22000 series SMEM parsing
kernel: wifi: iwlwifi: fix 22000 series SMEM parsing
A flaw was found in the Linux kernel's `iwlwifi` driver. This vulnerability occurs during SMEM parsing if the firmware reports an invalid number of Logical Media Access Controllers (LMACs), which can lead to an array overrun. This issue could potentially result in system instability or a denial of service (DoS).
Package: kernel (Red Hat Enterprise Linux 10) - Affected
Package: kernel (Red Hat Enterprise Linux 6) - Not affected
Package: kernel (Red Hat Enterprise Linux 7) - Affected
Package: kernel-rt (Red Hat Enterprise Linux 7) - Affected
Package: kernel (Red Hat Enterprise Linux 8) - Affected
Package: kernel-rt (Red Hat Enterprise Linux 8) - Affected
Package: kernel (Red Hat Enterprise Linux 9) - Affected
Package: kernel-rt (R
GHSA
GHSA-g3v6-g863-2542: In the Linux kernel, the following vulnerability has been resolved:
wifi: iwlwifi: fix 22000 series SMEM parsing
If the firmware were to report thre
ghsa_unreviewed·2026-05-06
CVE-2026-43172 GHSA-g3v6-g863-2542: In the Linux kernel, the following vulnerability has been resolved:
wifi: iwlwifi: fix 22000 series SMEM parsing
If the firmware were to report thre
In the Linux kernel, the following vulnerability has been resolved:
wifi: iwlwifi: fix 22000 series SMEM parsing
If the firmware were to report three LMACs (which doesn't
exist in hardware) then using "fwrt->smem_cfg.lmac[2]" is
an overrun of the array. Reject such and use IWL_FW_CHECK
instead of WARN_ON in this function.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-43172 kernel: wifi: iwlwifi: fix 22000 series SMEM parsing
bugzilla·2026-05-06
CVE-2026-43172 [MEDIUM] CVE-2026-43172 kernel: wifi: iwlwifi: fix 22000 series SMEM parsing
CVE-2026-43172 kernel: wifi: iwlwifi: fix 22000 series SMEM parsing
In the Linux kernel, the following vulnerability has been resolved:
wifi: iwlwifi: fix 22000 series SMEM parsing
If the firmware were to report three LMACs (which doesn't
exist in hardware) then using "fwrt->smem_cfg.lmac[2]" is
an overrun of the array. Reject such and use IWL_FW_CHECK
instead of WARN_ON in this function.
Discussion:
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2026050635-CVE-2026-43172-6ed1@gregkh/T
Rapid7
Patch Tuesday - May 2026
blogs_rapid7·2026-05-13·CVSS 10.0
CVE-2026-41089 [CRITICAL] Patch Tuesday - May 2026
Microsoft is publishing 137 vulnerabilities on May 2026 Patch Tuesday . Microsoft is not aware of exploitation in the wild or public disclosure for any of these vulnerabilities. So far this month, Microsoft has provided patches to address 133 browser vulnerabilities, which are not included in the Patch Tuesday count above.
## Windows Netlogon: critical RCE
Anyone responsible for securing a domain controller should prioritize remediation of CVE-2026-41089 , which is a critical stack-based buffer overflow in Windows Netlogon with a CVSS v3 base score of 9.8. Exploitation leads to execution in the context of the Netlogon service, so that’s SYSTEM privileges on the domain controller. For most pentesters, that’s the point at which the customer report more or less writes itself. No privileges
2026-05-06
Published