SB2026032578 - Improper Synchronization in Linux kernel wireless rsi driver
Published: March 25, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Improper Synchronization (CVE-ID: CVE-2026-23373)
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper return value handling in the rsi_mac80211_config function within the RSI Wi-Fi driver when configuring 802.11 hardware. A local user can trigger a misconfigured hardware initialization to cause a denial of service.
The issue arises because the driver defaults to returning -EOPNOTSUPP instead of 0 during configuration, which triggers a WARN_ON in ieee80211_hw_conf_init, leading to disruptive behavior.
Remediation
Install update from vendor's website.