{"id":"CVE-2026-80940","title":"kernel: wifi: rtw88: pci: fix resource leak on failed NAPI setup (CVE-2026-80940)","summary":"A flaw was found in the Linux kernel's rtw88 PCI driver. During the probe process, if the NAPI (Networked Attached Peripheral Interface) setup fails, allocated PCI resources are not properly released. This resource leak could potentially l…","severity":"medium","cvss":5.5,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","cvssSource":"vendor","cwe":"CWE-772","vendor":"Red Hat","product":"Red Hat Enterprise Linux 9","affected":["enterprise_linux 10","enterprise_linux 9","openshift_container_platform 4"],"published":"2026-09-11","updated":"2026-09-14","sourceUpdated":"2026-09-14T16:00:00+00:00","source":"CSAF","sourceUrl":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-80940.json","references":[{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-80940.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-80940"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2532366"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-80940"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-80940"},{"url":"https://git.kernel.org/pub/scm/linux/security/vulns.git/plain/cve/published/2026/CVE-2026-80940.mbox"},{"url":"https://git.kernel.org/stable/c/481fff9bda01720c70b19fb260808145a3f21594"},{"url":"https://git.kernel.org/stable/c/34a505071d1ffc5ebf3dc3cd16d2a12b044bcc84"},{"url":"https://git.kernel.org/stable/c/b1596e212ab1739930b25b9d3daf6b5cd307b537"},{"url":"https://git.kernel.org/stable/c/e779df4806cd29cbcca5c9dc0a1073662c76b889"}],"tags":["csaf","vex","red-hat","cve.org"],"epss":0.00168,"epssPercentile":0.0645,"ingestedAt":"2026-09-14T00:35:28.532Z","slug":"CVE-2026-80940","body":"## Overview\n\nA flaw was found in the Linux kernel's rtw88 PCI driver. During the probe process, if the NAPI (Networked Attached Peripheral Interface) setup fails, allocated PCI resources are not properly released. This resource leak could potentially lead to a Denial of Service (DoS) due to resource exhaustion, impacting system stability.\n\n## Vendor advisories\n\n- **Red Hat VEX** · Low · affected: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 9, Red Hat OpenShift Container Platform 4 · no fix planned: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 9, Red Hat OpenShift Container Platform 4 · updated 2026-09-14 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-80940.json)\n\n**kernel: wifi: rtw88: pci: fix resource leak on failed NAPI setup** — rated Low by Red Hat. Released 2026-09-11, updated 2026-09-14.\n\nAffected:\n\n- Red Hat Enterprise Linux 10\n- Red Hat Enterprise Linux 9\n- Red Hat OpenShift Container Platform 4\n\nNo fix planned:\n\n- Red Hat Enterprise Linux 10\n- Red Hat Enterprise Linux 9\n- Red Hat OpenShift Container Platform 4\n\nNot affected:\n\n- Red Hat Enterprise Linux 6\n- Red Hat Enterprise Linux 7\n- Red Hat Enterprise Linux 8\n- Red Hat OpenShift Container Platform 4\n\n## Remediation\n\nFix deferred","depth":"sunlit","depthScore":30,"depthScoreParts":{"impact":30.3,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[{"seq":202722,"id":"CVE-2026-80940","ts":1789403715284,"field":"cvss","old":null,"new":"5.5"},{"seq":202721,"id":"CVE-2026-80940","ts":1789403715284,"field":"severity","old":"none","new":"medium"},{"seq":147319,"id":"CVE-2026-80940","ts":1789270209457,"field":"cvss","old":null,"new":"4.1"},{"seq":147318,"id":"CVE-2026-80940","ts":1789270209457,"field":"severity","old":"none","new":"medium"},{"seq":109072,"id":"CVE-2026-80940","ts":1789183730198,"field":"cvss","old":null,"new":"4.1"},{"seq":109071,"id":"CVE-2026-80940","ts":1789183730198,"field":"severity","old":"none","new":"medium"}]}