CyberRota Analysis
AI-GeneratedThe vulnerability affects the Linux kernel's handling of individual TWT (Target Wake Time) parameters within the mac80211 subsystem, where insufficient validation of received S1G TWT setup frames can lead to the driver processing incomplete parameter structures. This could potentially allow an attacker to exploit the driver by sending malformed TWT setup frames, which may result in undefined behavior or system instability. Organizations using Linux-based systems that rely on the mac80211 subsystem for wireless communication should prioritize addressing this vulnerability to mitigate potential exploitation risks.
Original NVD Description
In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: validate individual TWT params before driver setup ieee80211_process_rx_twt_action() only partially validates a received S1G TWT setup frame before queueing it. An individual agreement can therefore reach ieee80211_s1g_rx_twt_setup() with twt->length too short for the full struct ieee80211_twt_params. The individual path passes twt to drv_add_twt_setup(). Both the tracepoint and the driver callback consume the complete parameters block, not merely req_type. Do not pass a short individual agreement to the driver. Broadcast agreements remain unchanged because they are rejected locally after accessing only req_type. [edit commit message to not overclaim lack of validation nor understate driver impact]