CVE-2026-80722

HIGHCVSS 8.8/10EPSS 0.16%

Last modified

CVE-2026-80722 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: validate individual TWT params before driver setup ieee80211_process_rx_twt_action() only partially validates a received S1G TWT setup frame before queueing it. An individual agreement can therefore reach ieee80211_s1g_rx_twt_setup() with twt->length too short for the full struct ieee80211_twt_params. The individual path passes twt to drv_add_twt_setup(). Both the tracepoint and the driver callback consume the complete parameters block, not merely req_type. EPSS estimates a 0.16% chance of exploitation in the next 30 days.

Description

In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: validate individual TWT params before driver setup ieee80211_process_rx_twt_action() only partially validates a received S1G TWT setup frame before queueing it. An individual agreement can therefore reach ieee80211_s1g_rx_twt_setup() with twt->length too short for the full struct ieee80211_twt_params. The individual path passes twt to drv_add_twt_setup(). Both the tracepoint and the driver callback consume the complete parameters block, not merely req_type. Do not pass a short individual agreement to the driver. Broadcast agreements remain unchanged because they are rejected locally after accessing only req_type. [edit commit message to not overclaim lack of validation nor understate driver impact]

Metrics

EPSS Probability
0.16%

5.5th percentile

Probability of exploitation in the next 30 days. Learn more

Affected Software

Source: CNA advisory (CVE.org). NVD analysis pending.

VendorProductVersions
LinuxLinux>= f5a4c24e689f54e66201f04d343bdd2e8a1d7923, < 92fcd0f30dc8e51f252589b082d46851d295cc1a; >= f5a4c24e689f54e66201f04d343bdd2e8a1d7923, < 09d60d1f72e6598241490eb6c4e97245af895c09; >= f5a4c24e689f54e66201f04d343bdd2e8a1d7923, < ff558072d199c1d641d1561da622e67f780514de; >= f5a4c24e689f54e66201f04d343bdd2e8a1d7923, < ade9e2f0f7f4d3089600ac2af8ef0b91746f923b; >= f5a4c24e689f54e66201f04d343bdd2e8a1d7923, < b558e07708d886acfcf4b0391ed7a8546e81d326; >= f5a4c24e689f54e66201f04d343bdd2e8a1d7923, < 47fb04c3826e1f90271d405523043d6708b9072a; >= f5a4c24e689f54e66201f04d343bdd2e8a1d7923, < 0502d5077e419427d80f4d46ba95d0067f5fb916
LinuxLinux5.15

References

Timeline

Published
Last Modified
Status
Received

Frequently Asked Questions

What is CVE-2026-80722?
In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: validate individual TWT params before driver setup ieee80211_process_rx_twt_action() only partially validates a received S1G TWT setup frame before queueing it. An individual agreement can therefore reach ieee80211_s1g_rx_twt_setup() with twt->length too short for the full struct ieee80211_twt_params. The individual path passes twt to drv_add_twt_setup(). Both the tracepoint and the driver callback consume the complete parameters block, not merely req_type. Do not pass a short individual agreement to the driver. Broadcast agreements remain unchanged because they are rejected locally after accessing only req_type. [edit commit message to not overclaim lack of validation nor understate driver impact]
How severe is CVE-2026-80722?
CVE-2026-80722 has a CVSS score of 8.8/10 (HIGH severity). The EPSS model estimates a 0.16% probability of exploitation in the next 30 days.
How do I fix CVE-2026-80722?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

How Strix Helps

Related CVEs from 2026

Are you affected by CVE-2026-80722?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST