Linux Kernel mac80211 TWT Param Validation Flaw (CVE-2026-80722)
CVE-2026-80722 Published on August 28, 2026
wifi: mac80211: validate individual TWT params before driver setup
In the Linux kernel, the following vulnerability has been resolved:
wifi: mac80211: validate individual TWT params before driver setup
ieee80211_process_rx_twt_action() only partially validates a received
S1G TWT setup frame before queueing it.
An individual agreement can therefore reach ieee80211_s1g_rx_twt_setup()
with twt->length too short for the full struct ieee80211_twt_params.
The individual path passes twt to drv_add_twt_setup(). Both the tracepoint
and the driver callback consume the complete parameters block, not merely
req_type. Do not pass a short individual agreement to the driver.
Broadcast agreements remain unchanged because they are rejected locally
after accessing only req_type.
[edit commit message to not overclaim lack of validation nor
understate driver impact]
Products Associated with CVE-2026-80722
Want to know whenever a new CVE is published for Linux Kernel? stack.watch will email you.
Affected Versions
Linux:- Version f5a4c24e689f54e66201f04d343bdd2e8a1d7923 and below 92fcd0f30dc8e51f252589b082d46851d295cc1a is affected.
- Version f5a4c24e689f54e66201f04d343bdd2e8a1d7923 and below 09d60d1f72e6598241490eb6c4e97245af895c09 is affected.
- Version f5a4c24e689f54e66201f04d343bdd2e8a1d7923 and below ff558072d199c1d641d1561da622e67f780514de is affected.
- Version f5a4c24e689f54e66201f04d343bdd2e8a1d7923 and below ade9e2f0f7f4d3089600ac2af8ef0b91746f923b is affected.
- Version f5a4c24e689f54e66201f04d343bdd2e8a1d7923 and below b558e07708d886acfcf4b0391ed7a8546e81d326 is affected.
- Version f5a4c24e689f54e66201f04d343bdd2e8a1d7923 and below 47fb04c3826e1f90271d405523043d6708b9072a is affected.
- Version f5a4c24e689f54e66201f04d343bdd2e8a1d7923 and below 0502d5077e419427d80f4d46ba95d0067f5fb916 is affected.
- Version 5.15 is affected.
- Before 5.15 is unaffected.
- Version 5.15.216, <= 5.15.* is unaffected.
- Version 6.1.183, <= 6.1.* is unaffected.
- Version 6.6.151, <= 6.6.* is unaffected.
- Version 6.12.103, <= 6.12.* is unaffected.
- Version 6.18.44, <= 6.18.* is unaffected.
- Version 7.1.8, <= 7.1.* is unaffected.
- Version 7.2, <= * is unaffected.