Security Flaw in the Linux Kernel's Wifi Driver Setup
CVE-2026-80722
What is CVE-2026-80722?
The Linux kernel contains a flaw within the wifi driver that improperly validates individual TWT parameters during the setup phase. Specifically, the method ieee80211_process_rx_twt_action() allows for incomplete validation, which may result in the driver receiving a TWT setup frame with a structure that is shorter than expected. This can lead to instability or unintended behavior when the driver attempts to process these unverified parameters. While broadcast agreements are correctly handled to prevent such issues, individual agreements can pose a security risk if not carefully managed. It's crucial for system administrators to ensure they are running updated versions of the Linux kernel to mitigate this issue.
Affected Version(s)
Linux f5a4c24e689f54e66201f04d343bdd2e8a1d7923 < 92fcd0f30dc8e51f252589b082d46851d295cc1a
Linux f5a4c24e689f54e66201f04d343bdd2e8a1d7923 < 09d60d1f72e6598241490eb6c4e97245af895c09
Linux f5a4c24e689f54e66201f04d343bdd2e8a1d7923