wifi: mac80211: validate individual TWT params before driver setup
Summary
| CVE | CVE-2026-80722 |
|---|---|
| State | PUBLISHED |
| Assigner | Linux |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-08-28 08:16:58 UTC |
| Updated | 2026-08-29 07:16:54 UTC |
| Description | In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: validate individual TWT params before driver setup ieee80211_process_rx_twt_action() only partially validates a received S1G TWT setup frame before queueing it. An individual agreement can therefore reach ieee80211_s1g_rx_twt_setup() with twt->length too short for the full struct ieee80211_twt_params. The individual path passes twt to drv_add_twt_setup(). Both the tracepoint and the driver callback consume the complete parameters block, not merely req_type. Do not pass a short individual agreement to the driver. Broadcast agreements remain unchanged because they are rejected locally after accessing only req_type. [edit commit message to not overclaim lack of validation nor understate driver impact] |
Risk And Classification
Primary CVSS: v3.1 8.8 HIGH from 416baaa9-dc9f-4396-8d5f-8c081fb06d67
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS: 0.001610000 probability, percentile 0.055150000 (date 2026-08-28)
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | Secondary | 8.8 | HIGH | CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| 3.1 | CNA | DECLARED | 8.8 | HIGH | CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
CVSS v3.1 Breakdown
Attack Vector
AdjacentAttack Complexity
LowPrivileges Required
NoneUser Interaction
NoneScope
UnchangedConfidentiality
HighIntegrity
HighAvailability
HighCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Linux | Linux | affected f5a4c24e689f54e66201f04d343bdd2e8a1d7923 92fcd0f30dc8e51f252589b082d46851d295cc1a git | Not specified |
| CNA | Linux | Linux | affected f5a4c24e689f54e66201f04d343bdd2e8a1d7923 09d60d1f72e6598241490eb6c4e97245af895c09 git | Not specified |
| CNA | Linux | Linux | affected f5a4c24e689f54e66201f04d343bdd2e8a1d7923 ff558072d199c1d641d1561da622e67f780514de git | Not specified |
| CNA | Linux | Linux | affected f5a4c24e689f54e66201f04d343bdd2e8a1d7923 ade9e2f0f7f4d3089600ac2af8ef0b91746f923b git | Not specified |
| CNA | Linux | Linux | affected f5a4c24e689f54e66201f04d343bdd2e8a1d7923 b558e07708d886acfcf4b0391ed7a8546e81d326 git | Not specified |
| CNA | Linux | Linux | affected f5a4c24e689f54e66201f04d343bdd2e8a1d7923 47fb04c3826e1f90271d405523043d6708b9072a git | Not specified |
| CNA | Linux | Linux | affected f5a4c24e689f54e66201f04d343bdd2e8a1d7923 0502d5077e419427d80f4d46ba95d0067f5fb916 git | Not specified |
| CNA | Linux | Linux | affected 5.15 | Not specified |
| CNA | Linux | Linux | unaffected 5.15 semver | Not specified |
| CNA | Linux | Linux | unaffected 5.15.216 5.15.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.1.183 6.1.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.6.151 6.6.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.12.103 6.12.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.18.44 6.18.* semver | Not specified |
| CNA | Linux | Linux | unaffected 7.1.8 7.1.* semver | Not specified |
| CNA | Linux | Linux | unaffected 7.2 * original_commit_for_fix | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| git.kernel.org/stable/c/0502d5077e419427d80f4d46ba95d0067f5fb916 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/ade9e2f0f7f4d3089600ac2af8ef0b91746f923b | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/47fb04c3826e1f90271d405523043d6708b9072a | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/ff558072d199c1d641d1561da622e67f780514de | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/b558e07708d886acfcf4b0391ed7a8546e81d326 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/92fcd0f30dc8e51f252589b082d46851d295cc1a | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/09d60d1f72e6598241490eb6c4e97245af895c09 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.