Answer in brief
CVE-2026-80722 records a Unknown severity vulnerability in wifi: mac80211: validate individual TWT params before driver setup. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=f5a4c24e689f54e66201f04d343bdd2e8a1d7923 <92fcd0f30dc8e51f252589b082d46851d295cc1a || >=f5a4c24e689f54e66201f04d343bdd2e8a1d7923 <09d60d1f72e6598241490eb6c4e97245af895c09 || >=f5a4c24e689f54e66201f04d343bdd2e8a1d7923 <ff558072d199c1d641d1561da622e67f780514de || >=f5a4c24e689f54e66201f04d343bdd2e8a1d7923 <ade9e2f0f7f4d3089600ac2af8ef0b91746f923b || >=f5a4c24e689f54e66201f04d343bdd2e8a1d7923 <b558e07708d886acfcf4b0391ed7a8546e81d326 || >=f5a4c24e689f54e66201f04d343bdd2e8a1d7923 <47fb04c3826e1f90271d405523043d6708b9072a || >=f5a4c24e689f54e66201f04d343bdd2e8a1d7923 <0502d5077e419427d80f4d46ba95d0067f5fb916 | 92fcd0f30dc8e51f252589b082d46851d295cc1a, 09d60d1f72e6598241490eb6c4e97245af895c09, ff558072d199c1d641d1561da622e67f780514de, ade9e2f0f7f4d3089600ac2af8ef0b91746f923b, b558e07708d886acfcf4b0391ed7a8546e81d326, 47fb04c3826e1f90271d405523043d6708b9072a, 0502d5077e419427d80f4d46ba95d0067f5fb916 |
| Linux/Linuxgeneric | 5.15 | Not reported |
Published upstream
Aug 28, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 28, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 28, 2026
In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: validate individual TWT params before driver setup ieee80211_process_rx_twt_action() only partially validates a received S1G TWT setup frame before queueing it. An individual agreement can therefore reach ieee80211_s1g_rx_twt_setup() with twt->length too short for the full struct ieee80211_twt_params. The individual path passes twt to drv_add_twt_setup(). Both the tracepoint and the driver callback consume the complete parameters block, not merely req_type. Do not pass a short individual agreement to the driver. Broadcast agreements remain unchanged because they are rejected locally after accessing only req_type. [edit commit message to not overclaim lack of validation nor understate driver impact]
Quoted source text, attributed separately from HOL analysis.