SB2026082837 - Out-of-bounds read in Linux kernel mac80211
Published: August 28, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Out-of-bounds read (CVE-ID: CVE-2026-80722)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to an out-of-bounds read in mac80211 TWT setup handling when processing a received S1G TWT setup frame. A remote attacker can send a specially crafted TWT setup frame with an individual agreement and a truncated parameters block to cause a denial of service.
Broadcast agreements are rejected locally after accessing only req_type.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/0502d5077e419427d80f4d46ba95d0067f5fb916
- https://git.kernel.org/stable/c/09d60d1f72e6598241490eb6c4e97245af895c09
- https://git.kernel.org/stable/c/47fb04c3826e1f90271d405523043d6708b9072a
- https://git.kernel.org/stable/c/92fcd0f30dc8e51f252589b082d46851d295cc1a
- https://git.kernel.org/stable/c/ade9e2f0f7f4d3089600ac2af8ef0b91746f923b
- https://git.kernel.org/stable/c/b558e07708d886acfcf4b0391ed7a8546e81d326
- https://git.kernel.org/stable/c/ff558072d199c1d641d1561da622e67f780514de