A vulnerability has been identified in the RTLWIFI driver, which is used to support Realtek Wi-Fi chips on Linux systems. The flaw in the driver could be exploited to destroy your device or even allow a hacker to take complete control of your system.
![]()
The bug has existed here for at least four years and is characterized as «critical» by security experts. It has been named CVE-2019-17666 and although a solution has been proposed to fix it, it has not yet been incorporated into the Linux kernel.
As Ars Technica notes, even if the patch is included in a future kernel update, users will have to wait a while for it to be included in Linux distros – and that could take some time.
Perhaps most interestingly, the attack can be triggered remotely, without any user intervention. Any Linux device with a Realtek chip is at risk, provided that Wi-Fi is enabled and it is in close proximity to a malicious machine.

Essentially, it exploits a vulnerability in a power-saving feature called Notice of Absence, which is built into Wi-Fi Direct (a standard that allows devices to connect to each other without a router). A hacker could add vendor-specific information to Wi-Fi beacons, which would cause a buffer overflow in the Linux kernel.
Both desktops and laptops with Linux distributions installed, as well as Android phones equipped with Realtek Wi-Fi chips, are vulnerable to the vulnerability.
