---
id: CVE-2026-46092
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  wifi: rtw88: check for PCI upstream bridge existence

  pci_upstream_bridge() returns NULL if the device is on a root bus
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  wifi: rtw88: check for PCI upstream bridge existence

  pci_upstream_bridge() returns NULL if the device is on a root bus.  If
  8821CE is installed in the system with such…
severity: medium
cvss: 5.5
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-476
vendor: linux
product: linux_kernel
affected:
  - 'linux_kernel >= 5.15.17, < 5.16'
  - 'linux_kernel >= 5.16.3, < 7.1'
patched:
  - linux_kernel 7.1
published: '2026-05-27'
updated: '2026-07-16'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-46092'
references:
  - url: 'https://git.kernel.org/stable/c/000134a20bbf89b1152520a2eef71f91fdb83a5b'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/3b89b4c095804c478d50376285e66700cf3c045f'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/3bbbb56204f7359ce2139a9341b43b52a186261c'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/6c53d68e3bcfc8faccdd76c3383a9232b05c9ae6'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/959c13da6c36167ce1016d400a6104d2367f686e'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/cc9b6303e7ea91bc360b42c7edc1fe9ceb2f47fe'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/eb101d2abdcccb514ca4fccd3b278dd8267374f6'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
tags:
  - nvd
epss: 0.00136
epssPercentile: 0.03388
ingestedAt: '2026-07-16T12:53:56.174Z'
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

wifi: rtw88: check for PCI upstream bridge existence

pci_upstream_bridge() returns NULL if the device is on a root bus.  If
8821CE is installed in the system with such a PCI topology, the probing
routine will crash.  This has probably been unnoticed as 8821CE is mostly
supplied in laptops where there is a PCI-to-PCI bridge located upstream
from the device.  However the card might be installed on a system with
different configuration.

Check if the bridge does exist for the specific workaround to be applied.

Found by Linux Verification Center (linuxtesting.org) with Svace static
analysis tool.

## Affected

- `linux_kernel >= 5.15.17, < 5.16`
- `linux_kernel >= 5.16.3, < 7.1`

## Remediation

Upgrade past the affected range:

- `linux_kernel 7.1`
