SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-80722

HIGH · CVSS 8.8 EPSS 0.24%

Source: NVD + CISA KEV + EPSS · Published 2026-08-28 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

The vulnerability affects the Linux kernel's handling of individual TWT (Target Wake Time) parameters within the mac80211 subsystem, where insufficient validation of received S1G TWT setup frames can lead to the driver processing incomplete parameter structures. This could potentially allow an attacker to exploit the driver by sending malformed TWT setup frames, which may result in undefined behavior or system instability. Organizations using Linux-based systems that rely on the mac80211 subsystem for wireless communication should prioritize addressing this vulnerability to mitigate potential exploitation risks.

CVE
CVE-2026-80722
Severity
HIGH
CVSS
8.8
EPSS
0.24%
Linux

Original NVD Description

In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: validate individual TWT params before driver setup ieee80211_process_rx_twt_action() only partially validates a received S1G TWT setup frame before queueing it. An individual agreement can therefore reach ieee80211_s1g_rx_twt_setup() with twt->length too short for the full struct ieee80211_twt_params. The individual path passes twt to drv_add_twt_setup(). Both the tracepoint and the driver callback consume the complete parameters block, not merely req_type. Do not pass a short individual agreement to the driver. Broadcast agreements remain unchanged because they are rejected locally after accessing only req_type. [edit commit message to not overclaim lack of validation nor understate driver impact]